High severity8.8NVD Advisory· Published May 26, 2023· Updated Jul 9, 2026
CVE-2023-33779
CVE-2023-33779
Description
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xuxueli:xxl-jobMaven | <= 2.4.1 | — |
Affected products
3- XXL-Job/XXL-Jobdescription
Patches
Vulnerability mechanics
References
4- github.com/silence-silence/xxl-job-lateral-privilege-escalation-vulnerability-/blob/main/README.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-9mmj-64jh-ph9cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33779ghsaADVISORY
- xxl-job.comghsaWEB
News mentions
0No linked articles in our index yet.