Record summary

CVE-2025-7901 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.8.0affected
4.8.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMyangzongzhuan RuoYi - DOM Based XSS

yangzongzhuan RuoYi = 4.8.1 contains a stored XSS caused by manipulation of the \"configUrl\" argument in /swagger-ui/index.html of Swagger UI, letting remote attackers execute scripts, exploit requires crafted request.

Impact

Remote attackers can execute arbitrary scripts in users' browsers, potentially stealing data or performing actions on behalf of users.

Remediation

Update to the latest version beyond 4.8.1.

AuthorsNikhil Patidar
Template tagscvecve2025headlessruoyixssswaggervuln
Shodan: html:"RuoYi"

Source: ProjectDiscovery

References

5