PT-2025-34168 · Xuxueli · Xxl-Job

Ez-Lbz

·

Published

2025-08-20

·

Updated

2025-08-21

·

CVE-2025-9263

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Xuxueli xxl-job versions up to 3.1.1
Description: A vulnerability exists in the getJobsByGroup function located in the /src/main/java/com/xxl/job/admin/controller/JobLogController.java file. Manipulation of the jobGroup argument results in improper control of resource identifiers, potentially allowing for remote exploitation. The exploit has been publicly disclosed and may be used.
Recommendations: Versions prior to 3.1.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-9263
GHSA-6RQ7-M52P-8PQG

Affected Products

Xxl-Job