zhijiantianya ruoyi-vue-pro
cpe:2.3:a:iocoder:ruoyi-vue-pro:*:*:*:*:*:*:*
- 2.4.1
A critical path traversal vulnerability has been identified in Zhijiantianya Ruoyi-Vue-Pro version 2.4.1. The issue arises in the backend file upload interface, specifically within the admin-api/infra/file/upload endpoint. The vulnerability allows for remote exploitation by manipulating the 'path' argument, potentially leading to unauthorized access to the file system.
Exploitation of this vulnerability allows for path traversal, which could be used to access files outside of the intended directory, potentially leading to the disclosure of sensitive information or further exploitation of the application.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.