CVE-2024-9048
- EPSS 0.37%
- Veröffentlicht 21.09.2024 09:15:04
- Zuletzt bearbeitet 30.09.2024 13:00:48
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.j...
CVE-2024-42900
- EPSS 0.34%
- Veröffentlicht 28.08.2024 16:15:09
- Zuletzt bearbeitet 14.05.2025 18:25:19
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.
CVE-2024-42913
- EPSS 0.35%
- Veröffentlicht 26.08.2024 18:15:07
- Zuletzt bearbeitet 26.03.2025 22:15:14
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
CVE-2024-41599
- EPSS 0.46%
- Veröffentlicht 19.07.2024 20:15:09
- Zuletzt bearbeitet 19.03.2025 18:15:21
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method
CVE-2024-6511
- EPSS 0.34%
- Veröffentlicht 04.07.2024 19:15:11
- Zuletzt bearbeitet 14.05.2025 18:24:38
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type Handler. The manipulation of the argument HttpHeaders.CONTENT_TYPE leads to...
CVE-2024-29400
- EPSS 0.64%
- Veröffentlicht 12.04.2024 07:15:08
- Zuletzt bearbeitet 14.05.2025 17:50:52
An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
CVE-2023-52048
- EPSS 0.34%
- Veröffentlicht 28.02.2024 20:15:41
- Zuletzt bearbeitet 28.04.2025 13:08:59
RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
CVE-2023-7133
- EPSS 0.68%
- Veröffentlicht 28.12.2023 18:15:45
- Zuletzt bearbeitet 21.11.2024 08:45:20
A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unknown code of the file /login of the component HTTP POST Request Handler. The manipulation of the argument rememberMe with the input...
CVE-2023-49371
- EPSS 3.66%
- Veröffentlicht 01.12.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:17
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
CVE-2021-28411
- EPSS 0.75%
- Veröffentlicht 11.08.2023 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:38
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.