Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2020-28435 Vulnerability in npm package ffmpeg-sdk
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-28426 Vulnerability in npm package kill-process-on-port