CVE-2022-29770: XSS
Published Jun 3, 2022
·Updated
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
Affected Software
1 affected component
Xuxueli xxl-job=2.3.0
Event History
Jun 3, 2022
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29770?
The severity of CVE-2022-29770 is medium with a CVSS score of 5.4.
2
How does XXL-Job v2.3.0 contain a stored cross-site scripting (XSS) vulnerability?
XXL-Job v2.3.0 contains a stored cross-site scripting (XSS) vulnerability via the /xxl-job-admin/jobinfo endpoint.
3
What is the affected software version of CVE-2022-29770?
The affected software version of CVE-2022-29770 is XXL-Job v2.3.0.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2022-29770.
5
Is there a reference link for more information about this vulnerability?
Yes, you can find more information about this vulnerability at https://github.com/xuxueli/xxl-job/issues/2836.