Description
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/1921
Related Vulnerabilities
CVE-2020-7687 Vulnerability in npm package fast-http
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2017-16082 Vulnerability in maven package org.webjars.npm:pg
CVE-2023-28640 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2020-19698 Vulnerability in maven package org.webjars.bower:editor.md