CVE-2025-2707
CVSS 3.1 Score 6 of 10 (medium)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 78
Summary
CVE-2025-2707 is a critical vulnerability affecting zhijiantianya ruoyi-vue-pro version 2.4.1. The issue lies within the unknown functionality of the /app-api/infra/file/upload component's Front-End Store Interface. An attacker can exploit this path traversal vulnerability by manipulating the argument path. This exploit can be launched remotely, and the public disclosure of the vulnerability increases the risk of its use in malicious activities. Despite early contact, the vendor has not responded to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.