A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another users account via a crafted POST request to the component /jobinfo/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xxl-job | Xuxueli | 2.4.1 (including) | 2.4.1 (including) |