A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://vuldb.com/?id.317015 | technical description vdb entry |
https://vuldb.com/?ctiid.317015 | signature permissions required |
https://vuldb.com/?submit.618353 | third party advisory |
https://github.com/yangzongzhuan/RuoYi/issues/293 | issue tracking |