Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2022-22963 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-core
CVE-2017-16139 Vulnerability in npm package jikes
CVE-2011-1077 Vulnerability in maven package org.apache.archiva:archiva
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-28469 Vulnerability in maven package org.webjars.bowergithub.es128:glob-parent