CVE-2020-24922: CSRF
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0 allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
Other sources
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24922?
CVE-2020-24922 is a Cross-Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0.
How severe is CVE-2020-24922?
CVE-2020-24922 has a severity score of 8.8 (high).
How does CVE-2020-24922 allow for remote code execution?
CVE-2020-24922 allows remote attackers to execute arbitrary code and escalate privileges via a crafted .html file.
Which software versions are affected by CVE-2020-24922?
Version 2.2.0 of xuxueli xxl-job is affected by CVE-2020-24922.
How can I fix CVE-2020-24922?
To fix CVE-2020-24922, update to a version of xuxueli xxl-job that is not affected by the vulnerability.