Skip to main content

Vendor archive

xuxueli CVEs

Beta · best-effort

29 CVEs tagged to vendor xuxueli1 Critical, 11 High, 9 Medium, 8 Low, 0 Unrated.

CVE-2020-29204

Published Dec 27, 2020

XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23814

Published Sep 3, 2020

Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23811

Published Sep 3, 2020

xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20094

Published Dec 12, 2018

An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfControlle…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-29 of 29 CVEsPage 2 of 2