CVE-2025-7906: yangzongzhuan RuoYi CommonController.java uploadFile unrestricted upload
Published Jul 20, 2025
·Updated
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
yangzongzhuan RuoYi<=4.8.1
Ruoyi Ruoyi<=4.8.1
Event History
Jul 20, 2025
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 18, 58473
Event
via NVD·03:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7906?
CVE-2025-7906 is classified as a critical vulnerability.
2
How do I fix CVE-2025-7906?
To fix CVE-2025-7906, upgrade to versions of RuoYi beyond 4.8.1.
3
What component is affected by CVE-2025-7906?
CVE-2025-7906 affects the uploadFile function in the CommonController.java file.
4
What type of vulnerability is CVE-2025-7906?
CVE-2025-7906 is an unrestricted file upload vulnerability.
5
Which versions of RuoYi are impacted by CVE-2025-7906?
RuoYi versions up to and including 4.8.1 are impacted by CVE-2025-7906.