A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Configurations
No configuration.
History
22 Jul 2025, 13:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-18 15:15
Updated : 2025-07-22 13:06
NVD link : CVE-2025-7787
Mitre link : CVE-2025-7787
CVE.ORG link : CVE-2025-7787
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)