CVE 5.3 MEDIUM

Xuxueli xxl-job Jobs JobInfoController.java remove resource injection_CVE-2025-9264

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Basic Information

ID CVE-2025-9264
Source VulDB
Published Aug 20, 2025 at 23:32

Affected Product

Vendor Xuxueli
Product xxl-job
Version 3.1.0
Affected Versions Xuxueli xxl-job 3.1.0
Xuxueli xxl-job 3.1.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.