PT-2020-17110 · Xxl-Job · Xxl-Job

Steward007

·

Published

2020-12-27

·

Updated

2021-10-12

·

CVE-2020-29204

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions XXL-JOB version 2.2.0
Description The issue allows Stored XSS in the Add User feature, bypassing the 20-character limit via the UserController.java file in xxl-job-admin. This can be exploited through the xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java file.
Recommendations For XXL-JOB version 2.2.0, consider disabling the UserController.java function temporarily until a patch is available to prevent exploitation of the Stored XSS vulnerability. Restrict access to the Add User feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29204
GHSA-WC73-W5R9-X9PC

Affected Products

Xxl-Job