zhijiantianya ruoyi-vue-pro
cpe:2.3:a:iocoder:ruoyi-vue-pro:*:*:*:*:*:*:*
- 2.4.1
A critical path traversal vulnerability has been identified in Zhijiantianya Ruoyi-Vue-Pro version 2.4.1. The issue arises in the Front-End Store Interface, specifically within the file upload functionality of the app-api/infra/file endpoint. The vulnerability allows for manipulation of the path argument, potentially leading to unauthorized access to files. This issue can be exploited remotely.
Exploitation of this vulnerability allows for path traversal, which could lead to unauthorized file access on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.