在 Xuxueli 的 xxl-job(版本 3.4.2 及更早)中发现一个漏洞。该漏洞影响了文件 中某项未明确说明的功能。该操作导致权限管理不当。攻击者可以远程发起攻击。漏洞利用方法已公开披露,并可能被实际利用。安全研究人员曾提前联系供应商,但供应商未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90488 | 6.3 MEDIUM | Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injection |
| CVE-2026-90489 | 3.5 LOW | Xuxueli xxl-job insert cross site scripting |
No comments yet