A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.
Link | Tags |
---|---|
https://vuldb.com/?id.317017 | vdb entry |
https://vuldb.com/?ctiid.317017 | signature permissions required |
https://vuldb.com/?submit.618357 | third party advisory |
https://github.com/yangzongzhuan/RuoYi/issues/295 | exploit issue tracking |