CVE-2020-24922

Description

Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

References

ExploitIssue TrackingVendor Advisory

CvssV3 impact

Could not find any metrics

CvssV2 impact

Could not find any metrics