y_project
18 exploits
Active since Mar 2022
RuoYi v4.7.2 - CSV Injection via Log File Export
RuoYi < 4.7.7 - Cross-Site Scripting via File Upload originalFilenames Parameter
RuoYi < 4.7.7 - Uncontrolled Resource Consumption via filterKeyword Function
RuoYi < 4.7.6 - Arbitrary File Download via Background Management Module
RuoYi < 4.7.5 - SQL Injection via /tool/gen/createTable
y_project RuoYi <4.7.5 - SQL Injection
RuoYi < 4.7.3 - Arbitrary File Upload and Remote Code Execution via HTML File
RuoYi 4.7.2 - Incorrect Permission Assignment for Critical Resource via /system/user/resetPwd
RuoYi < 4.7.9 - SQL Injection via SqlUtil.java createTable Function
RuoYi < 4.7.9 - Cross-Site Scripting in Backend User Import via loginName
RuoYi < 4.7.9 - Cross-Site Scripting in Backend User Import via loginName
RuoYi < 4.7.9 - Cross-Site Scripting via Content-Type Handler
Ruoyi 4.8.1 - Privilege Escalation via Department Ownership
Ruoyi v4.8.0 - Improper Access Control in SysUserController authRole Method
Ruoyi v4.8.0 - Improper Access Control in SysUserController resetPwd Method
RuoYi 4.8.2 - Unauthenticated Sensitive Data Exposure via selectDept Function
RuoYi 4.8.2 - Unauthenticated Improper Access Control in Update Function
RuoYi-Cloud - Cross-Site Scripting in JSON Handler