CVE-2020-23811: Xuxueli Xxl-Job

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

Affected products

  • Xuxueli Xxl-Job: version 2.2.0 only

Published 2020-09-03. Last modified 2026-06-17.