Cross Site Scripting Vulnerability in YunaiV File Upload Component
CVE-2026-97322
5.3MEDIUM
What is CVE-2026-97322?
A cross site scripting vulnerability has been identified in the file upload component of YunaiV's zhijiantianya ruoyi-vue-pro application. This vulnerability is triggered by an unknown function within FileController.java, located in the yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file directory. The exploit can be executed remotely, placing users at risk of malicious attacks. Despite early notification, the vendor has yet to respond to this disclosure, heightening concerns related to potential exploitation.
Affected Version(s)
ruoyi-vue-pro 2026.08
ruoyi-vue-pro 2026.08
