PT-2025-37740 · Yangzongzhuan · Ruoyi
Tobbe
·
Published
2025-09-15
·
Updated
2025-09-20
·
CVE-2025-10473
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
yangzongzhuan RuoYi versions up to 4.8.1
Description
A security flaw has been discovered in yangzongzhuan RuoYi. This impacts the
filterKeyword function of the file /com/ruoyi/common/utils/sql/SqlUtil.java within the Blacklist Handler component, resulting in SQL injection. The attack may be launched remotely.Recommendations
Versions prior to 4.8.1 should be used.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi