First published: Sun Dec 27 2020(Updated: )
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-29204.
The title of this vulnerability is XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src…
The affected software is XXL-JOB 2.2.0.
The severity of this vulnerability is medium with a CVSS score of 6.1.
The vulnerability can be exploited by an attacker injecting malicious code into the Add User feature of the XXL-JOB 2.2.0 application.