Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv4m-h859-jwmq

Опубликовано: 04 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Cross-Site Request Forgery in XXL Job

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.

Пакеты

Наименование

com.xuxueli:xxl-job

maven
Затронутые версииВерсия исправления

<= 2.3.1

Отсутствует

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352