Beveiligingsadvies

CVE-2025-67342

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-12 00:00:00
Laatst bijgewerkt 2025-12-12 19:16:42
Toegewezen door mitre
CVSS-score 4.6
Status PUBLISHED

Beschrijving

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.