CVE-2025-9263 | Xuxueli xxl-job up to 3.1.1 JobLogController.java getJobsByGroup jobGroup resource injection (Issue 3772)
A vulnerability categorized as problematic has been discovered in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2025-9263. The attack may be launched remotely. Furthermore, there is an exploit available.