CVE-2025-7789 is a problematic vulnerability in Xuxueli xxl-job up to version 3.1.1, specifically affecting the token generation function in the IndexController.java file. The vulnerability, classified as CWE-326 and CWE-916, allows for the generation of password hashes with insufficient computational effort. While remotely exploitable, the attack complexity is high, and exploitation is considered difficult, resulting in a low CVSS score of 3.7. There is no evidence of active exploitation, and despite public disclosure of the exploit, there are no known Metasploit or Nuclei modules, nor any entries in ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.1CPE matchmatch criteria | cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.