CVE 5.3 MEDIUM

yangzongzhuan RuoYi Swagger UI index.html cross site scripting_CVE-2025-7901

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

Description

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.

Basic Information

ID CVE-2025-7901
Source VulDB
Published Jul 20, 2025 at 15:32
Modified Jul 21, 2025 at 20:36

Affected Product

Vendor yangzongzhuan
Product RuoYi
Version 4.8.0
Affected Versions yangzongzhuan RuoYi 4.8.0
yangzongzhuan RuoYi 4.8.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.