Path Traversal Vulnerability in zhijiantianya Ruoyi-Vue-Pro Backend File Upload Interface
CVE-2025-2708
9.1CRITICAL
What is CVE-2025-2708?
A path traversal vulnerability exists in the zhijiantianya Ruoyi-Vue-Pro 2.4.1 application, specifically in the Backend File Upload Interface. Malicious users could exploit this weakness to manipulate the argument path, potentially allowing unauthorized access to restricted directories and files. This vulnerability can be exploited remotely, making it a significant concern for users of the affected product. Despite the responsible disclosure of this issue to the vendor, no corrective measures have been implemented to date.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
