在 yangzongzhuan 维护的 RuoYi-Vue 版本(最高至 3.9.2)中发现了一个安全漏洞。该漏洞影响 Common Download Endpoint 组件中的文件 的 / 功能。通过对参数 / 进行操纵,可导致路径遍历漏洞。攻击者可以远程发起攻击。该漏洞的利用方法已被公开,可被恶意利用。项目方已通过问题报告早期知晓该问题,但至今尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yangzongzhuan | RuoYi-Vue | 3.9.0 |
affected |
3.9.1 |
affected | ||
3.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yangzongzhuan | RuoYi-Vue | 3.9.0 |
cpe:2.3:a:yangzongzhuan:ruoyi-vue:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet