CVE-2022-32065: XSS
Published Jul 13, 2022
·Updated
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.
Affected Software
1 affected component
Ruoyi Ruoyi<=4.7.3
Remediation
Event History
Jul 13, 2022
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Frequently Asked Questions
1
What is CVE-2022-32065?
CVE-2022-32065 is an arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below.
2
How can an attacker exploit CVE-2022-32065?
Attackers can exploit CVE-2022-32065 by uploading a crafted HTML file that allows them to execute arbitrary code.
3
What is the severity of CVE-2022-32065?
CVE-2022-32065 has a severity level of medium with a CVSS score of 5.4.
4
What is the affected software?
The affected software is RuoYi v4.7.3 and below.
5
How do I fix the vulnerability?
To fix the vulnerability, update RuoYi to a version higher than 4.7.3.