CVE-2023-33779

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/05/2023
Last modified:
14/01/2025

Description

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xuxueli:xxl-job:2.4.1:*:*:*:*:*:*:*