Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
References
Link | Resource |
---|---|
https://github.com/xuxueli/xxl-job/issues/1921 | Exploit Issue Tracking Vendor Advisory |
https://github.com/xuxueli/xxl-job/issues/1921 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-08-11 14:15
Updated : 2024-11-21 05:16
NVD link : CVE-2020-24922
Mitre link : CVE-2020-24922
CVE.ORG link : CVE-2020-24922
JSON object : View
Products Affected
xuxueli
- xxl-job
CWE
CWE-352
Cross-Site Request Forgery (CSRF)