VendorsXuxuelixxl-job2.4.1
Vulnerabilities

Xuxueli XXL-JOB 2.4.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-33779
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
Published 2023-05-26 · Modified
8.8EPSS 0.009
CVE-2024-42681
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
Published 2024-08-15 · Modified
8.8EPSS 0.009