Metrics
Affected Vendors & Products
Mon, 30 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ruoyi
Ruoyi ruoyi |
|
CPEs | cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ruoyi
Ruoyi ruoyi |
Mon, 23 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Y Project
Y Project ruoyi |
|
CPEs | cpe:2.3:a:y_project:ruoyi:*:*:*:*:*:*:*:* | |
Vendors & Products |
Y Project
Y Project ruoyi |
|
Metrics |
ssvc
|
Sat, 21 Sep 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The patch is named 9b68013b2af87b9c809c4637299abd929bc73510. It is recommended to apply a patch to fix this issue. | |
Title | y_project RuoYi Backend User Import SysUserServiceImpl.java SysUserServiceImpl cross site scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-09-21T08:31:19.316Z
Updated: 2024-09-23T15:51:04.588Z
Reserved: 2024-09-20T15:35:06.043Z
Link: CVE-2024-9048
Updated: 2024-09-23T15:50:57.352Z
Status : Analyzed
Published: 2024-09-21T09:15:04.660
Modified: 2024-09-30T13:00:48.613
Link: CVE-2024-9048
No data.