Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2083
Related Vulnerabilities
CVE-2020-19697 Vulnerability in npm package editor.md
CVE-2021-32640 Vulnerability in npm package ws
CVE-2023-0410 Vulnerability in npm package @builder.io/qwik
CVE-2023-37958 Vulnerability in maven package org.jenkins-ci.plugins:sumologic-publisher
CVE-2021-37137 Vulnerability in maven package io.netty:netty-codec