2 results (0.005 seconds)

CVSS: 6.3EPSS: 0%CPEs: 10EXPL: 1

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java of the component Backend User Import. The manipulation of the argument loginName leads to cross site scripting. The attack can be launched remotely. • https://vuldb.com/?id.278215 https://vuldb.com/?ctiid.278215 https://gitee.com/y_project/RuoYi/issues/IAR6Q3 https://gitee.com/y_project/RuoYi/issues/IAR6Q3#note_31993641_link https://gitee.com/y_project/RuoYi/commit/9b68013b2af87b9c809c4637299abd929bc73510 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 10EXPL: 1

A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type Handler. The manipulation of the argument HttpHeaders.CONTENT_TYPE leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://gitee.com/y_project/RuoYi/issues/IA8O7O https://vuldb.com/?ctiid.270343 https://vuldb.com/?id.270343 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •