CVE-2023-27025

HIGH7.5EPSS 0.14%

RuoYi vulnerable to arbitrary file download

Published: 4/2/2023Modified: 7/16/2025

Description

An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (4)