Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.
PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.
PowerJob V4.3.1 is vulnerable to Insecure Permissions via the list job interface.
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.