CVE-2025-9264: Xuxueli xxl-job Jobs JobInfoController.java remove resource injection
A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9264?
CVE-2025-9264 is classified as a medium severity vulnerability.
How do I fix CVE-2025-9264?
To mitigate CVE-2025-9264, upgrade Xuxueli xxl-job to version 3.1.2 or later.
What components are affected by CVE-2025-9264?
CVE-2025-9264 affects the Jobs Handler component, specifically the remove function in the JobInfoController.java file.
What type of attack does CVE-2025-9264 expose my system to?
CVE-2025-9264 exposes the system to potential unauthorized access due to improper control of the argument ID.
Is CVE-2025-9264 exploitable remotely?
Yes, CVE-2025-9264 can potentially be exploited remotely by manipulating the ID argument.