CVE-2020-29204: XSS
Published Dec 27, 2020
·Updated
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Affected Software
1 affected component
Xuxueli xxl-job=2.2.0
Event History
Dec 27, 2020
CVE Published
via MITRE·05:36 AM
Data Sourced
via MITRE·05:36 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-29204.
2
What is the title of this vulnerability?
The title of this vulnerability is XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src…
3
What is the affected software?
The affected software is XXL-JOB 2.2.0.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.1.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by an attacker injecting malicious code into the Add User feature of the XXL-JOB 2.2.0 application.