A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/yangzongzhuan/RuoYi/issues/295 | Exploit Vendor Advisory Issue Tracking |
https://vuldb.com/?ctiid.317017 | Permissions Required VDB Entry |
https://vuldb.com/?id.317017 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.618357 | Third Party Advisory VDB Entry |
Configurations
History
11 Sep 2025, 15:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:* | |
First Time |
Ruoyi ruoyi
Ruoyi |
|
References | () https://github.com/yangzongzhuan/RuoYi/issues/295 - Exploit, Vendor Advisory, Issue Tracking | |
References | () https://vuldb.com/?ctiid.317017 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.317017 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.618357 - Third Party Advisory, VDB Entry |
22 Jul 2025, 13:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Jul 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-20 17:15
Updated : 2025-09-11 15:31
NVD link : CVE-2025-7903
Mitre link : CVE-2025-7903
CVE.ORG link : CVE-2025-7903
JSON object : View
Products Affected
ruoyi
- ruoyi
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames