Impact
A reflected cross‑site scripting flaw exists in the Task Management interface of xuxueli xxl‑job, where the name and author parameters of JobInfoController.java are not properly sanitized before being rendered. An attacker can craft a malicious URL containing JavaScript that will be executed in the browser of any authenticated user who views the affected page, allowing theft of session cookies, credential hijacking or execution of arbitrary actions on the victim’s behalf. The CVE description confirms that the attack can be initiated remotely and is publicly disclosed.
Affected Systems
xuxueli xxl‑job versions up to 3.4.2 and 3.5.0 are affected. No newer releases are listed as fixed in the provided data.
Risk and Exploitability
The flaw carries a CVSS score of 5.1, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Nevertheless, because the issue is remote and can be triggered with a crafted request, any organization hosting these versions is at risk of cross‑site scripting attacks, potentially compromising user accounts and data.
OpenCVE Enrichment