CVE-2020-23814 describes multiple stored cross-site scripting (XSS) vulnerabilities in xuxueli xxl-job version 2.2.0. Specifically, these flaws allow remote attackers to inject arbitrary web scripts or HTML through the AppName and AddressList parameters within the JobGroupController.java file. With a CVSS score of 6.1 (Medium), this vulnerability has a network attack vector and low attack complexity, requiring user interaction to exploit, and could lead to limited confidentiality and integrity impacts. The FAUCET Risk Score is high at 82/100, indicating a significant potential risk despite the medium CVSS score. There is no evidence of active exploitation, nor is it listed in the CISA KEV catalog. While no Metasploit modules or ExploitDB entries exist, Nuclei templates are available for detecting this stored XSS. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:xuxueli:xxl-job:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.