9.4

CVE-2025-66916

Exploit
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DromaraRuoyi-vue-plus Version <= 5.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://gitee.com/dromara/RuoYi-Vue-Plus
Product
https://github.com/Catherines77/code-au/blob/main/ruoyi-vue-plus/QLExpress.md
Third Party Advisory
Exploit
https://gist.github.com/Catherines77/e3f06b9c4cc6298579e858088a243c3d
Third Party Advisory