CVE-2025-2040: zhijiantianya ruoyi-vue-pro deploy special elements used in a template engine
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2040?
CVE-2025-2040 is classified as a critical severity vulnerability.
What kind of attack does CVE-2025-2040 facilitate?
CVE-2025-2040 facilitates improper neutralization of special elements used in a template engine.
What is the affected software version for CVE-2025-2040?
CVE-2025-2040 affects version 2.4.1 of the zhijiantianya ruoyi-vue-pro software.
How do I fix CVE-2025-2040?
To fix CVE-2025-2040, it is recommended to update the zhijiantianya ruoyi-vue-pro software to the latest version.
Where is the vulnerability located in CVE-2025-2040?
The vulnerability in CVE-2025-2040 is located in the file /admin-api/bpm/model/deploy.