Cross Site Scripting Vulnerability in XXL Job Admin by Xuxueli
CVE-2023-48088
5.4MEDIUM
What is CVE-2023-48088?
XXL Job Admin version 2.4.0 is susceptible to Cross Site Scripting (XSS) attacks through the endpoint /xxl-job-admin/joblog/logDetailPage. This vulnerability allows attackers to inject malicious scripts into the web interface, potentially compromising user sessions, stealing sensitive information, or performing unauthorized actions. Proper validation and sanitization measures should be implemented to mitigate this risk.