Improper Authorization in YunaiV zhijiantianya ruoyi-vue-pro Payment System
CVE-2026-97324

6.9MEDIUM

Key Information:

Vendor

Yunaiv

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97324?

A vulnerability has been found in the payment system of YunaiV's zhijiantianya ruoyi-vue-pro, specifically in the updateDemoOrderPaid function within the PayDemoOrderController class. This vulnerability stems from improper handling of the ID argument, which allows for unauthorized access to payment functionalities. The exploit can be executed remotely and is publicly accessible, raising significant security concerns. This issue has been reported to the vendor; however, there has been no response regarding the mitigation of the flaw. Users of this product are advised to remain vigilant and implement necessary security measures.

Affected Version(s)

ruoyi-vue-pro 2026.08

ruoyi-vue-pro 2026.08

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liuyulin (VulDB User)
VulDB CNA Team
.