← back
CVE-2025-7901

yangzongzhuan RuoYi Swagger UI index.html cross site scripting

CVSS 5.3 MEDIUMEPSS 0.7%CWE-79CWE-94
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Affected products
yangzongzhuan · RuoYi

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →