5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Basic Information
ID
CVE-2025-9264
Source
VulDB
Published
Aug 20, 2025 at 23:32
Affected Product
Vendor
Xuxueli
Product
xxl-job
Version
3.1.0
Affected Versions
Xuxueli xxl-job 3.1.0
Xuxueli xxl-job 3.1.1
Xuxueli xxl-job 3.1.1