Medium severity4.3NVD Advisory· Published Feb 4, 2023· Updated Jun 17, 2026
CVE-2023-0674
CVE-2023-0674
Description
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xuxueli:xxl-jobMaven | <= 2.3.1 | — |
Affected products
3- XXL-JOB/XXL-JOBdescription
Patches
Vulnerability mechanics
References
5- github.com/boyi0508/xxl-job-explain/blob/main/README.mdnvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-pv4m-h859-jwmqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-0674ghsaADVISORY
- vuldb.comnvdPermissions RequiredThird Party AdvisoryWEB
- vuldb.comnvdPermissions RequiredThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.