描述
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
AI分析AI驱动
受影响产品
ruoyiruoyi
参考资料
- https://github.com/yangzongzhuan/RuoYi/issues/293ExploitIssue TrackingVendor Advisory
- https://vuldb.com/?ctiid.317015Permissions RequiredVDB Entry
- https://vuldb.com/?id.317015Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.618353Third Party AdvisoryVDB Entry