A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the function uploadFilesPath
of the component File Upload
. The manipulation of the argument originalFilenames
leads to cross site scripting. The attack may be launched remotely. VDB-235118 is the identifier assigned to this vulnerability.
GSA_kwCzR0hTQS1wNHd3LWo0cHItcXc2cc4AA01M
RuoYi vulnerable to Cross-site Scripting
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
maven:com.ruoyi:ruoyi | <= 4.7.7 | No known fixed version | |
|