First published: Mon Apr 10 2023(Updated: )
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-26120.
All versions of the package com.xuxueli:xxl-job are affected by this vulnerability.
The vulnerability can be exploited by executing HTML uploaded payload through the /xxl-job-admin/user/add and /xxl-job-admin/user/update endpoints.
The severity of this vulnerability is medium with a CVSS score of 6.1.
It is recommended to update to a fixed version of the package as soon as it becomes available.