PT-2025-34169 · Xxl-Job · Xxl-Job

Ez-Lbz

·

Published

2025-08-20

·

Updated

2025-08-21

·

CVE-2025-9264

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Xuxueli xxl-job versions up to 3.1.1
Description: A vulnerability exists in Xuxueli xxl-job. The issue affects the remove function within the /src/main/java/com/xxl/job/admin/controller/JobInfoController.java file of the Jobs Handler component. Manipulation of the ID argument leads to improper control of resource identifiers, potentially allowing for remote exploitation. The exploit for this issue has been publicly released.
Recommendations: Versions prior to 3.1.1 are affected.

Exploit

Fix

RCE

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-9264
GHSA-GJX6-H8HM-C9RQ

Affected Products

Xxl-Job