← Back

CVE-2025-67342

nvd nist
Published: Dec 12, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users, any user with menu modification permissions can impact all users by exploiting this stored XSS vulnerability.

Affected (1)

Products: Ruoyi: Ruoyi
1 product
Ruoyi
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.8.1

References (1)

Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.