Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 Maven

xxl-job Jobs Handler remove function allows improper control of resource identifiers via ID parameter

GHSA-gjx6-h8hm-c9rq · CVE-2025-9264

Published · Modified

Description

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes