Unrated severityNVD Advisory· Published Jul 20, 2025· Updated Jul 21, 2025
yangzongzhuan RuoYi Swagger UI index.html cross site scripting
CVE-2025-7901
Description
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
Affected products
1- Range: 4.8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- vuldb.commitrethird-party-advisory
- github.com/yangzongzhuan/RuoYi/issues/293mitreissue-tracking
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
News mentions
0No linked articles in our index yet.