Beveiligingsadvies

CVE-2026-9374

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-24 10:30:10
Laatst bijgewerkt 2026-05-26 16:16:57
Toegewezen door VulDB
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.