A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
| Software | From | Fixed in |
|---|---|---|
| xuxueli / xxl-job | 2.3.0 | 2.3.0.x |
com.xuxueli / xxl-job
|
- | 2.3.0.x |