CVE-2025-7907: yangzongzhuan RuoYi Druid application-druid.yml default credentials
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/resources/application-druid.yml of the component Druid. The manipulation leads to use of default credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7907?
CVE-2025-7907 is classified as problematic due to the use of default credentials.
How do I fix CVE-2025-7907?
To fix CVE-2025-7907, change the default credentials in the application-druid.yml file.
What software is affected by CVE-2025-7907?
CVE-2025-7907 affects yangzongzhuan RuoYi versions up to 4.8.1.
What component is involved in CVE-2025-7907?
The vulnerability in CVE-2025-7907 involves the Druid component within the application.
Can CVE-2025-7907 lead to unauthorized access?
Yes, CVE-2025-7907 can lead to unauthorized access due to the use of default credentials.