Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
| Software | From | Fixed in |
|---|---|---|
com.xuxueli / xxl-job
|
- | 2.2.0.x |
| xuxueli / xxl-job | 2.2.0 | 2.2.0.x |