CVE-2023-0674: XXL-JOB New Password updatePwd cross-site request forgery
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this XXL-JOB vulnerability?
The vulnerability ID is CVE-2023-0674.
What is the severity rating of CVE-2023-0674?
The severity rating of CVE-2023-0674 is medium (6.5).
What component in XXL-JOB is affected by CVE-2023-0674?
The New Password Handler component in XXL-JOB is affected by CVE-2023-0674.
How can the vulnerability CVE-2023-0674 be exploited?
CVE-2023-0674 can be exploited through cross-site request forgery (CSRF).
Are there any references related to CVE-2023-0674?
Yes, you can find references to CVE-2023-0674 at the following links: [Reference 1](https://vuldb.com/?id.220196), [Reference 2](https://vuldb.com/?ctiid.220196), [Reference 3](https://github.com/boyi0508/xxl-job-explain/blob/main/README.md).