Lateral Privilege Escalation in XXL-Job by Xuxueli
CVE-2023-33779
8.8HIGH
What is CVE-2023-33779?
A vulnerability in XXL-Job version 2.4.1 permits users to execute arbitrary commands on another user's account. This is achieved by sending a specially crafted POST request to the /jobinfo/ component. This flaw allows for unauthorized access and manipulation of user accounts, leading to potential data breaches and operational disruption.