XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.xuxueli:xxl-job-core(Maven) | 0 | 2.3.0 | N/A |
CVSS Metrics