A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
| Software | From | Fixed in |
|---|---|---|
com.xuxueli / xxl-job
|
- | 2.4.1.x |
| xuxueli / xxl-job | 2.4.1 | 2.4.1.x |