Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1191 | This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update. |
Github GHSA |
GHSA-4j2p-x79m-jcj8 | XXL-JOB vulnerable to Cross-site Scripting |
| Link | Providers |
|---|---|
| https://security.snyk.io/vuln/SNYK-JAVA-COMXUXUELI-3248764 |
|
Fri, 07 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-02-07T20:10:54.134Z
Reserved: 2023-02-20T10:28:48.923Z
Link: CVE-2023-26120
Updated: 2024-08-02T11:39:06.555Z
Status : Modified
Published: 2023-04-10T05:15:07.003
Modified: 2025-02-07T21:15:11.380
Link: CVE-2023-26120
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA