PT-2023-23404 · Unknown · Y Project Ruoyi

Springkill

·

Published

2023-06-08

·

Updated

2024-05-17

·

CVE-2023-3163

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions y project RuoYi versions up to 4.7.7
Description A vulnerability was found in the function filterKeyword. The manipulation of the argument value leads to resource consumption.
Recommendations For versions up to 4.7.7, consider disabling the filterKeyword function until a patch is available to prevent resource consumption due to argument manipulation.

Exploit

Fix

SQL injection

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-3163
GHSA-G3HH-Q55F-9G3W

Affected Products

Y Project Ruoyi