Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2023-37953 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2020-28268 Vulnerability in npm package controlled-merge
CVE-2022-25885 Vulnerability in npm package muhammara
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.velocity
CVE-2022-38750 Vulnerability in maven package org.yaml:snakeyaml