Description
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3329
Related Vulnerabilities
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2021-43306 Vulnerability in maven package org.webjars.bower:jquery-validation
CVE-2022-4348 Vulnerability in maven package com.ruoyi:ruoyi-common
CVE-2018-3721 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash