Description
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
Remediation
References
https://security.snyk.io/vuln/SNYK-JAVA-COMXUXUELI-3248764
Related Vulnerabilities
CVE-2020-15228 Vulnerability in npm package @actions/core
CVE-2023-41835 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-28500 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2021-39234 Vulnerability in maven package org.apache.ozone:ozone-common
CVE-2020-28471 Vulnerability in npm package properties-reader