Medium severity5.4GHSA Advisory· Published Apr 10, 2023· Updated Jun 17, 2026
CVE-2023-26120
CVE-2023-26120
Description
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xuxueli:xxl-jobMaven | <= 2.4.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
3- security.snyk.io/vuln/SNYK-JAVA-COMXUXUELI-3248764nvdExploitTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-4j2p-x79m-jcj8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26120ghsaADVISORY
News mentions
0No linked articles in our index yet.