CVE-2023-27025

HIGH

RuoYi < 4.7.6 - Arbitrary File Download via Background Management Module

Title source: llm
STIX 2.1

Description

An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 34.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-494
Status published
Products (2)
com.ruoyi/ruoyi 0 - 4.7.7Maven
ruoyi/ruoyi < 4.7.6
Published Apr 02, 2023
Tracked Since Feb 18, 2026