5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-7906
Source
VulDB
Published
Jul 20, 2025 at 19:32
Modified
Jul 21, 2025 at 15:52
Affected Product
Vendor
yangzongzhuan
Product
RuoYi
Version
4.8.0
Affected Versions
yangzongzhuan RuoYi 4.8.0
yangzongzhuan RuoYi 4.8.1
yangzongzhuan RuoYi 4.8.1