PT-2023-26321 · Unknown · Y Project Ruoyi

Zh5507158

·

Published

2023-07-21

·

Updated

2024-05-17

·

CVE-2023-3815

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions y project RuoYi versions up to 4.7.7
Description A vulnerability has been found in the function uploadFilesPath of the component File Upload. The manipulation of the argument originalFilenames leads to cross site scripting. The attack may be launched remotely.
Recommendations For y project RuoYi versions up to 4.7.7, consider disabling the uploadFilesPath function until a patch is available. Restrict access to the File Upload component to minimize the risk of exploitation. Avoid using the originalFilenames argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-3815
GHSA-P4WW-J4PR-QW6Q

Affected Products

Y Project Ruoyi