Impact
Xux any release up to 3.5.0, includes a cross‑site scripting flaw in the /jobinfo/insert API. An attacker can supply malicious content in the name or author parameters, which can be reflected to users who view the inserted job record, leading to execution of arbitrary scripts in the browser. This flaw is related to CWE‑79 and CWE‑94. The flaw is triggered by normal HTTP requests and does not require elevated privileges on the target system.
Affected Systems
Any deployment of Xuxueli xxl‑job that includes the /jobinfo/insert endpoint and is running version 3.5.0 or earlier is potentially impacted, as referenced by the CNA product name Xuxueli:xxl‑job.
Risk and Exploitability
The CVSS base score of 5.1 places the vulnerability in the medium severity range. The EPSS score of <1% indicates a low probability of exploitation, but the publicly available exploit means attackers have ready‑made tools to target the flaw by sending crafted HTTP requests to the /jobinfo/insert endpoint. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment