Ruoyi

Ruoyi

59 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.51%
  • Veröffentlicht 21.07.2023 05:15:15
  • Zuletzt bearbeitet 21.11.2024 08:18:08

A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the function uploadFilesPath of the component File Upload. The manipulation of the argument originalFilenames leads to cros...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 08.06.2023 14:15:15
  • Zuletzt bearbeitet 21.11.2024 08:16:35

A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the function filterKeyword. The manipulation of the argument value leads to resource consumption. VDB-231090 is the identifier assigned to th...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.04.2023 01:15:07
  • Zuletzt bearbeitet 18.02.2025 16:15:14

An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 02.02.2023 22:15:12
  • Zuletzt bearbeitet 26.03.2025 20:15:17

RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.

  • EPSS 1.03%
  • Veröffentlicht 16.12.2022 22:15:08
  • Zuletzt bearbeitet 21.04.2025 14:15:21

Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

Exploit
  • EPSS 0.82%
  • Veröffentlicht 16.12.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:35:30

A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to sql injection. The name of the ...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 13.07.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:05:44

An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 30.03.2022 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:23

RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 30.03.2022 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:49:23

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.