PT-2026-98250 · Unknown · Ruoyi-Vue-Pro
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ruoyi-vue-pro versions prior to 2026.09
Description
A cross site scripting issue exists in the File Upload component within the file
yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java. This flaw allows a remote attacker to perform a manipulation that executes malicious scripts in the context of a user's session.Recommendations
Update ruoyi-vue-pro to a version newer than 2026.08.
Restrict access to the
FileController.java file within the File Upload component to minimize the risk of exploitation.Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi-Vue-Pro