Security Advisory

CVE-2025-7902

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-20 16:02:05
Last updated 2025-07-21 18:38:28
Assigner VulDB
CVSS score not scored
State PUBLISHED

Description

A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/web/controller/system/SysNoticeController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.