Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RuoYi-Vue-Plus 安全漏洞
Vulnerability Description
RuoYi-Vue-Plus是中国dromara组织的一个开发框架。 RuoYi-Vue-Plus 5.5.1及之前版本存在安全漏洞,该漏洞源于未过滤用户输入,可能导致任意文件读写。
CVSS Information
N/A
Vulnerability Type
N/A