Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2023-26115 Vulnerability in maven package org.webjars.npm:word-wrap
CVE-2021-31405 Vulnerability in maven package com.vaadin:vaadin-text-field-flow
CVE-2020-36379 Vulnerability in npm package aaptjs
CVE-2017-11556 Vulnerability in npm package node-sass
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-coyote