漏洞标题
y_project RuoYi File Upload 上传文件路径 跨站脚本
漏洞描述信息
y_project RuoYi 文件上传 uploadFilesPath 跨站脚本攻击
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
y_project RuoYi File Upload uploadFilesPath cross site scripting
漏洞描述信息
A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the function uploadFilesPath of the component File Upload. The manipulation of the argument originalFilenames leads to cross site scripting. The attack may be launched remotely. VDB-235118 is the identifier assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
RuoYi 跨站脚本漏洞
漏洞描述信息
RuoYi是中国若依(RuoYi)个人开发者的一款后台管理系统。 RuoYi 4.7.7之前版本存在跨站脚本漏洞,该漏洞源于File Upload组件中的uploadFilesPath函数存在安全问题, 通过参数originalFilenames 导致跨站脚本。
CVSS信息
N/A
漏洞类别
跨站脚本