Description
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
Remediation
References
https://security.snyk.io/vuln/SNYK-JAVA-COMXUXUELI-3248764
Related Vulnerabilities
CVE-2021-23330 Vulnerability in npm package launchpad
CVE-2011-1077 Vulnerability in maven package org.apache.archiva:archiva
CVE-2019-15903 Vulnerability in npm package dbus
CVE-2023-29205 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-xwiki
CVE-2021-4245 Vulnerability in maven package org.webjars.npm:rfc6902