Vulnerabilities (CVE)

Filtered by vendor Xuxueli Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48089 1 Xuxueli 1 Xxl-job 2023-11-21 N/A 8.8 HIGH
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CVE-2020-24922 1 Xuxueli 1 Xxl-job 2023-08-17 N/A 8.8 HIGH
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
CVE-2022-29002 1 Xuxueli 1 Xxl-job 2022-06-07 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
CVE-2020-23811 1 Xuxueli 1 Xxl-job 2021-07-21 5.0 MEDIUM 7.5 HIGH
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
CVE-2018-20094 1 Xuxueli 1 Xxl-conf 2019-01-04 5.0 MEDIUM 7.5 HIGH
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.