zhijiantianya ruoyi-vue-pro
cpe:2.3:a:iocoder:ruoyi-vue-pro:*:*:*:*:*:*:*
- 2.4.1
A critical vulnerability allowing improper neutralization of special elements in a template engine has been identified in Zhijiantianya Ruoyi-Vue-Pro version 2.4.1. This issue resides in an unknown functionality of the file '/admin-api/bpm/model/deploy', and can be exploited remotely.
Exploitation of this vulnerability could lead to arbitrary code execution on the server, as the improper neutralization of template elements could be used to inject and execute malicious code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.