XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
| Software | From | Fixed in |
|---|---|---|
| xuxueli / xxl-job | 2.2.0 | 2.2.0.x |
com.xuxueli / xxl-job-core
|
- | 2.3.0 |