在 Xuxueli 开发的 xxl-job 版本 3.4.2 及以下版本中确认存在一个安全漏洞。该漏洞影响了 文件中的 函数。对该函数的操纵可导致代码注入。攻击者可远程利用该漏洞。此漏洞的利用方式已被公开披露,因此可能被实际利用。供应商虽在漏洞披露初期即被联系,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90487 | 4.3 MEDIUM | Xuxueli xxl-job JobGroupController.java privileges management |
| CVE-2026-90489 | 3.5 LOW | Xuxueli xxl-job insert cross site scripting |
No comments yet