yangzongzhuan RuoYi = 4.8.1 contains a stored XSS caused by manipulation of the \"configUrl\" argument in /swagger-ui/index.html of Swagger UI, letting remote attackers execute scripts, exploit requires crafted request.
id: CVE-2025-7901
info:
name: yangzongzhuan RuoYi - DOM Based XSS
author: Nikhil Patidar
seve
...