Description
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
Remediation
References
https://security.snyk.io/vuln/SNYK-JAVA-COMXUXUELI-3248764
Related Vulnerabilities
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2023-28155 Vulnerability in npm package request
CVE-2020-7597 Vulnerability in npm package codecov
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2020-8840 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind