Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2016-4055 Vulnerability in maven package org.webjars.bower:moment
CVE-2021-23358 Vulnerability in maven package org.webjars.bowergithub.jashkenas:underscore
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-api
CVE-2021-26272 Vulnerability in npm package ckeditor4-dev
CVE-2021-20220 Vulnerability in maven package io.undertow:undertow-core