CVE-2023-27025
7.5HIGHAn arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
Published: 4/2/2023Updated: 2/18/2025
Description
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
AI AnalysisPowered by AI
Affected Products
ruoyiruoyi
References
- https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0Permissions Required
- https://gitee.com/y_project/RuoYi/issues/I697Q5ExploitIssue Tracking
- https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0Permissions Required
- https://gitee.com/y_project/RuoYi/issues/I697Q5ExploitIssue Tracking