Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjx6-h8hm-c9rq

Опубликовано: 21 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 5.4

Описание

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-639
CWE-99

Связанные уязвимости

CVSS3: 5.4
nvd
6 месяцев назад

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-639
CWE-99