Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67342

Опубликовано: 12 дек. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*
Версия до 4.8.1 (включая)

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
github
около 2 месяцев назад

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79