Path Traversal Vulnerability in zhijiantianya ruoyi-vue-pro by zhijiantianya
CVE-2025-2743
Key Information:
- Vendor
- Zhijiantianya
- Status
- Ruoyi-vue-pro
- Vendor
- CVE Published:
- 25 March 2025
Badges
Summary
A path traversal vulnerability exists in the Material Upload Interface of the ruoyi-vue-pro version 2.4.1. The flaw allows attackers to manipulate the File argument in the /admin-api/mp/material/upload-temporary endpoint, potentially leading to unauthorized file access or deletion. This attack can be executed remotely, posing significant risks should it be exploited. The vendor was notified about the issue but has not provided any response, alerting users to the urgency of addressing this vulnerability.
Affected Version(s)
ruoyi-vue-pro 2.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved