CVE-2025-7901: Cross Site Scripting in yangzongzhuan RuoYi
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
CVE-2025-7901: Cross Site Scripting in yangzongzhuan RuoYi
Description
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-19T14:08:11.164Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687d0f3fa83201eaac034b3a
Added to database: 7/20/2025, 3:46:07 PM
Last updated: 7/20/2025, 3:46:07 PM
Views: 1
Related Threats
CVE-2025-7898: Unrestricted Upload in Codecanyon iDentSoft
MediumCVE-2025-7897: Missing Authentication in harry0703 MoneyPrinterTurbo
MediumCVE-2025-7896: Path Traversal in harry0703 MoneyPrinterTurbo
MediumCVE-2025-46385: CWE-918 Server-Side Request Forgery (SSRF) in Emby Windows
HighCVE-2025-46384: CWE-434 Unrestricted Upload of File with Dangerous Type in Emby Windows
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.