CVE-2023-33779: Xuxueli Xxl-Job

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.

Affected products

  • Xuxueli Xxl-Job: version 2.4.1 only

Published 2023-05-26. Last modified 2026-07-09.