PT-2025-30218 · Druid+1 · Druid+1

Zast.Ai

·

Published

2025-07-20

·

Updated

2025-08-08

·

CVE-2025-7907

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions yangzongzhuan RuoYi versions up to 4.8.1
Description A problematic issue exists in yangzongzhuan RuoYi. The issue involves the use of default credentials within an unknown function of the ruoyi-admin/src/main/resources/application-druid.yml file of the Druid component. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 4.8.1 should be used. Consider restricting access to the application-druid.yml file to mitigate the risk.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-7907

Affected Products

Druid
Ruoyi