Impact
A client‑side scripting flaw exists in xuxueli xxl‑job, allowing a remote attacker to inject malicious code by manipulating the Name argument during a job group insertion. This vulnerability falls under the Cross‑Site Scripting weakness (CWE‑79) and could also be interpreted as enabling arbitrary code execution through script injection (CWE‑94). If exploited, it can allow an attacker to hijack user sessions, deface the console, or steal credentials from unsuspecting users.
Affected Systems
The flaw is present in all xuxueli xxl‑job installations up to and including version 3.5.0. The specific code path resides in the /jobgroup/insert functionality of the application.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.1 and has no publicly available EPSS score, indicating uncertainty about the frequency of exploitation. The flaw is not listed in CISA's KEV catalog. Attackers can trigger the issue by remotely crafting a request to the /jobgroup/insert endpoint with a malicious Name value, exploiting the lack of proper input validation or output escaping. The public disclosure of the exploit suggests it can be weaponized by threat actors.
OpenCVE Enrichment