Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XXL-JOB接口api/registry存在存储型XSS漏洞,当管理员登录后台触发XSS,攻击者可通过XSS获取管理员登录凭证进而实现远程命令执行 #3542

Closed
zhangyu007 opened this issue Sep 12, 2024 · 1 comment

Comments

@zhangyu007
Copy link

Please answer some questions before submitting your issue. Thanks!

Which version of XXL-JOB do you using?

Expected behavior

Actual behavior

Steps to reproduce the behavior

Other information

@xuxueli
Copy link
Owner

xuxueli commented Nov 10, 2024

无法复现,待提供复现步骤。

@xuxueli xuxueli closed this as completed Nov 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants