github.comissue trackingexploit
https://github.com/yangzongzhuan/RuoYi/issues/298 CVE-2025-8847
MEDIUM
yangzongzhuan RuoYi edit cross site scripting
Record summary
CVE-2025-8847 has a selected CVSS score of 5.1 (medium).
Description
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of the argument noticeTitle/noticeContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 4.8.0 | affected | |
| 4.8.1 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-8847 VDB-319381 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.319381 VDB-319381 | yangzongzhuan RuoYi edit cross site scriptingvdb entryTechnical description
https://vuldb.com/?id.319381 Submit #623372 | yangzongzhuan RuoYi <=4.8.1 cross site scriptingThird-party advisory
https://vuldb.com/?submit.623372