Description
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
Remediation
References
https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0
https://gitee.com/y_project/RuoYi/issues/I697Q5
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars:codemirror
CVE-2023-26475 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2021-21193 Vulnerability in maven package org.webjars.npm:electron