'; } else{ echo ''; } echo '
|
|
|||
Release Date:2026/6/1
Rule Name:CVE-2025-7788:XXL-JOB Remote Command Execution Vulnerability
Severity:high
CVE ID:CVE-2025-7788
| Descripiton:
|
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This interface is designed for authorized users to execute commands , if triggering rules, Please verify that the command comes from a legitimate request by a user with the necessary permissions. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.