Path Traversal Vulnerability in YunaiV/zhijiantianya ruoyi-vue-pro File Upload
CVE-2026-97323
5.3MEDIUM
What is CVE-2026-97323?
A vulnerability exists in YunaiV/zhijiantianya ruoyi-vue-pro that allows attackers to exploit the function 'getOriginalFilename' within the File Upload component, specifically in the 'MpMaterialServiceImpl.java' file. This flaw can lead to an unauthorized path traversal, enabling remote attackers to manipulate file paths and potentially access sensitive files on the server. The issue has been publicly disclosed, putting users at risk. Notably, the vendor was informed of this vulnerability prior to the public disclosure but did not respond or take action.
Affected Version(s)
ruoyi-vue-pro 2026.08
ruoyi-vue-pro 2026.08
