Ruoyi

Ruoyi

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.42%
  • Veröffentlicht 07.04.2025 00:00:00
  • Zuletzt bearbeitet 09.04.2025 17:29:47

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

Exploit
  • EPSS 0.31%
  • Veröffentlicht 29.01.2025 15:15:17
  • Zuletzt bearbeitet 14.05.2025 18:26:47

An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 29.01.2025 15:15:17
  • Zuletzt bearbeitet 14.05.2025 18:26:41

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 29.01.2025 15:15:17
  • Zuletzt bearbeitet 14.05.2025 18:26:33

RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 29.01.2025 15:15:17
  • Zuletzt bearbeitet 14.05.2025 18:26:10

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.

  • EPSS 0.23%
  • Veröffentlicht 27.01.2025 19:15:19
  • Zuletzt bearbeitet 13.05.2025 20:47:37

A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. The attack can be initiated remotely....

Exploit
  • EPSS 0.09%
  • Veröffentlicht 09.01.2025 20:15:39
  • Zuletzt bearbeitet 14.05.2025 18:26:00

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.

  • EPSS 0.4%
  • Veröffentlicht 07.10.2024 18:15:04
  • Zuletzt bearbeitet 15.05.2025 09:32:00

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

  • EPSS 0.14%
  • Veröffentlicht 21.09.2024 09:15:04
  • Zuletzt bearbeitet 30.09.2024 13:00:48

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.j...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 28.08.2024 16:15:09
  • Zuletzt bearbeitet 14.05.2025 18:25:19

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.