{"id":"GHSA-6w2f-6wq3-rjvf","summary":"RuoYi 4.7.3 vulnerable to arbitrary file upload in background management module","details":"An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.","aliases":["CVE-2022-32065"],"modified":"2023-11-08T04:09:33.559337Z","published":"2022-07-14T00:00:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-15T18:14:24Z","nvd_published_at":"2022-07-13T15:15:00Z","cwe_ids":["CWE-434","CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32065"},{"type":"WEB","url":"https://github.com/yangzongzhuan/RuoYi/issues/118"},{"type":"WEB","url":"https://github.com/yangzongzhuan/RuoYi/commit/d8b2a9a905fb750fa60e2400238cf4750a77c5e6"},{"type":"WEB","url":"https://gitee.com/y_project/RuoYi/commit/d8b2a9a905fb750fa60e2400238cf4750a77c5e6"},{"type":"WEB","url":"https://gitee.com/y_project/RuoYi/issues/I57IME"},{"type":"WEB","url":"https://github.com/yangzongzhuan/RuoYi"}],"affected":[{"package":{"name":"com.ruoyi:ruoyi","ecosystem":"Maven","purl":"pkg:maven/com.ruoyi/ruoyi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-6w2f-6wq3-rjvf/GHSA-6w2f-6wq3-rjvf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}