CVE-2022-23868: High severity ruoyi ruoyi-cloud vulnerability
Published Mar 30, 2022
·Updated
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
Affected Software
1 affected component
Ruoyi Ruoyi=4.7.2
Event History
Mar 30, 2022
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue in RuoYi v4.7.2?
The vulnerability ID for this security issue in RuoYi v4.7.2 is CVE-2022-23868.
2
What is the severity rating of CVE-2022-23868?
CVE-2022-23868 has a severity rating of 7.8, which is considered high.
3
What is the affected software version of CVE-2022-23868?
The affected software version of CVE-2022-23868 is Ruoyi v4.7.2.
4
How does the vulnerability occur in RuoYi v4.7.2?
The vulnerability in RuoYi v4.7.2 occurs through ruoyi-admin when a victim opens a .xlsx log file, allowing CSV injection.
5
Is there a fix available for CVE-2022-23868?
To fix CVE-2022-23868, it is recommended to update RuoYi to a version that addresses the vulnerability.