PT-2025-51988 · Y · Ruoyi

Customer

·

Published

2025-12-18

·

Updated

2025-12-30

·

CVE-2025-14856

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions y project RuoYi versions up to 4.8.1
Description A security issue exists in y project RuoYi, potentially allowing for remote code injection. The issue is related to manipulation of the fragment argument within an unknown function in the /monitor/cache/getnames file. The exploit for this issue has been publicly disclosed.
Recommendations Versions prior to 4.8.1 should be updated.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-14856

Affected Products

Ruoyi