CVE-2025-10218
- EPSS 0.03%
- Veröffentlicht 10.09.2025 21:32:05
- Zuletzt bearbeitet 16.10.2025 16:07:42
A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the component Background Management Page. This manipulation of the argument sortName causes sql injection. Rem...
CVE-2025-9413
- EPSS 0.03%
- Veröffentlicht 25.08.2025 18:02:08
- Zuletzt bearbeitet 09.10.2025 17:34:52
A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument orderByColumn/isAsc causes sql injection. The attack may be initiated r...
CVE-2025-9412
- EPSS 0.03%
- Veröffentlicht 25.08.2025 17:32:07
- Zuletzt bearbeitet 09.10.2025 17:42:10
A vulnerability was detected in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the argument orderByColumn/isAsc results in sql injection. The attack can be...
CVE-2025-9411
- EPSS 0.03%
- Veröffentlicht 25.08.2025 17:02:06
- Zuletzt bearbeitet 09.10.2025 17:47:12
A security vulnerability has been detected in lostvip-com ruoyi-go up to 2.1. The impacted element is the function SelectPageList of the file modules/system/service/LoginInforService.go. The manipulation of the argument isAsc leads to sql injection. ...
CVE-2025-9410
- EPSS 0.03%
- Veröffentlicht 25.08.2025 16:32:06
- Zuletzt bearbeitet 06.10.2025 18:15:32
A weakness has been identified in lostvip-com ruoyi-go up to 2.1. The affected element is the function SelectListByPage of the file modules/system/dao/GenTableDao.go. Executing manipulation of the argument isAsc/orderByColumn can lead to sql injectio...
CVE-2025-9409
- EPSS 0.1%
- Veröffentlicht 25.08.2025 16:02:07
- Zuletzt bearbeitet 06.10.2025 18:19:08
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system/controller/CommonController.go. Performing manipulation of the argument fileName results in path tra...