Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
yangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookie
Vulnerability Description
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue of the component Password Handler. The manipulation leads to cleartext storage of sensitive information in a cookie. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
在Cookie中的明文存储
Vulnerability Title
RuoYi 安全漏洞
Vulnerability Description
RuoYi是中国若依(RuoYi)个人开发者的一款后台管理系统。 RuoYi 3.8.9及之前版本存在安全漏洞,该漏洞源于对文件ruoyi-ui/jsencrypt.js和ruoyi-ui/login.vue的错误操作导致敏感信息明文存储在cookie中。
CVSS Information
N/A
Vulnerability Type
N/A