First published: Sat Feb 04 2023(Updated: )
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job | =2.3.1 | |
=2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-0674.
The severity rating of CVE-2023-0674 is medium (6.5).
The New Password Handler component in XXL-JOB is affected by CVE-2023-0674.
CVE-2023-0674 can be exploited through cross-site request forgery (CSRF).
Yes, you can find references to CVE-2023-0674 at the following links: [Reference 1](https://vuldb.com/?id.220196), [Reference 2](https://vuldb.com/?ctiid.220196), [Reference 3](https://github.com/boyi0508/xxl-job-explain/blob/main/README.md).