CVE-2025-9264 MEDIUM

CVE-2025-9264: Xuxueli xxl-job Jobs JobInfoController.java remove resource injection

Vendor Xuxueli
Product xxl-job
Weakness CWE-99
Published August 20, 2025
Last update August 21, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Key dates

Disclosure timeline

August 20, 2025 CVE published
August 21, 2025 Record updated