PT-2025-30218 · Druid +1 · Druid +1

Zast.Ai

·

Published

2025-07-20

·

Updated

2025-08-08

·

CVE-2025-7907

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions yangzongzhuan RuoYi versions up to 4.8.1
Description A problematic issue exists in yangzongzhuan RuoYi. The issue involves the use of default credentials within an unknown function of the
ruoyi-admin/src/main/resources/application-druid.yml
file of the Druid component. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 4.8.1 should be used. Consider restricting access to the
application-druid.yml
file to mitigate the risk.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-7907

Affected Products

Druid
Ruoyi