Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cmr-m8h4-f7xj

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
около 2 месяцев назад

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79