在 Dromara Skyeye 项目(截至提交哈希值 003549ae5615bd114ba5bb8ddf6a8e8ead97c321)中,bundled(内置)的 xxl-job-admin 的 JobInfoController 控制器中存在一个缺失身份验证漏洞。具体而言,某些被 @PermissionLimit(limit = false) 注解标识的端点未实施必要的身份验证检查。 未认证的攻击者可以向 /jobinfo/addAndStart 端点提交 POST 请求,构造恶意载荷以添加并启动类型为 GL
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-107780 | 9.8 CRITICAL | Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter |
| CVE-2026-107781 | 7.4 HIGH | Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById |
No comments yet