Cross-Site Request Forgery in XXL Job
Moderate severity
GitHub Reviewed
Published
Feb 4, 2023
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Description
Published by the National Vulnerability Database
Feb 4, 2023
Published to the GitHub Advisory Database
Feb 4, 2023
Last updated
Feb 14, 2023
Reviewed
Feb 14, 2023
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
References