Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7475 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Mon, 07 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iocoder
Iocoder ruoyi-vue-pro |
|
| CPEs | cpe:2.3:a:iocoder:ruoyi-vue-pro:2.4.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Iocoder
Iocoder ruoyi-vue-pro |
Thu, 06 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine | |
| Weaknesses | CWE-1336 CWE-791 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-03-06T20:23:45.787Z
Reserved: 2025-03-06T09:27:39.518Z
Link: CVE-2025-2040
Updated: 2025-03-06T20:23:40.493Z
Status : Analyzed
Published: 2025-03-06T20:15:38.920
Modified: 2025-07-07T18:29:28.303
Link: CVE-2025-2040
No data.
OpenCVE Enrichment
No data.
EUVD