CVE-2025-7901
yangzongzhuan RuoYi Swagger UI index.html cross site scripting
Record summary
CVE-2025-7901 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 4.8.0 | affected | |
| 4.8.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMyangzongzhuan RuoYi - DOM Based XSS
yangzongzhuan RuoYi = 4.8.1 contains a stored XSS caused by manipulation of the \"configUrl\" argument in /swagger-ui/index.html of Swagger UI, letting remote attackers execute scripts, exploit requires crafted request.
Impact
Remote attackers can execute arbitrary scripts in users' browsers, potentially stealing data or performing actions on behalf of users.
Remediation
Update to the latest version beyond 4.8.1.
Source: ProjectDiscovery