Description
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
Remediation
References
https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0
https://gitee.com/y_project/RuoYi/issues/I697Q5
Related Vulnerabilities
CVE-2017-16138 Vulnerability in maven package org.webjars.npm:mime
CVE-2020-19697 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2020-28447 Vulnerability in npm package xopen
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes
CVE-2020-6429 Vulnerability in maven package org.webjars.npm:electron