Impact
The vulnerability is a path traversal flaw in the Common Download Endpoint of yangzongzhuan's RuoYi-Vue application. The fileDownload/resourceDownload function can be manipulated by providing a crafted fileName or resource argument that causes the server to resolve a path outside the intended directory. This flaw allows an attacker to read arbitrary files on the server, potentially exposing sensitive data, configuration files, or credentials. The flaw is exploitable remotely and the public exploit has already been released, indicating that attackers can perform the attack from outside the network.
Affected Systems
The flaw affects all installations of yangzongzhuan RuoYi-Vue versions up to 3.9.2. Users running these or earlier releases are susceptible; newer releases are assumed to contain a fix but verification is recommended.
Risk and Exploitability
The CVSS score assigned to the flaw is 5.3, indicating a moderate risk. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Because the attack can be launched remotely without any special privileges, the threat manifests as a remote file read that could lead to the disclosure of confidential data. The publicly disclosed exploit demonstrates that an adversary can readily target vulnerable systems without significant barriers.
OpenCVE Enrichment