CVE-2025-2708
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 434
Summary
CVE-2025-2708 is a newly disclosed critical vulnerability affecting the Backend File Upload Interface component in zhijiantianya ruoyi-vue-pro version 2.4.1. The issue lies within the /admin-api/infra/file/upload path, which can be manipulated to enable path traversal. An attacker can initiate this attack remotely, leading to potential security risks. The vulnerability has been made public, and although the vendor was notified, no response was received. This increases the urgency for users to apply patches or workarounds to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Animate On Scroll