{"id":"GHSA-p4ww-j4pr-qw6q","summary":"RuoYi vulnerable to Cross-site Scripting","details":"A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the function `uploadFilesPath` of the component `File Upload`. The manipulation of the argument `originalFilenames` leads to cross site scripting. The attack may be launched remotely. VDB-235118 is the identifier assigned to this vulnerability.","aliases":["CVE-2023-3815"],"modified":"2023-11-08T04:13:06.524547Z","published":"2023-07-21T06:30:17Z","database_specific":{"nvd_published_at":"2023-07-21T05:15:15Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-07-21T20:18:40Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3815"},{"type":"PACKAGE","url":"https://gitee.com/y_project/RuoYi"},{"type":"WEB","url":"https://gitee.com/y_project/RuoYi/issues/I7IL85"},{"type":"WEB","url":"https://vuldb.com/?ctiid.235118"},{"type":"WEB","url":"https://vuldb.com/?id.235118"}],"affected":[{"package":{"name":"com.ruoyi:ruoyi","ecosystem":"Maven","purl":"pkg:maven/com.ruoyi/ruoyi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.7.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-p4ww-j4pr-qw6q/GHSA-p4ww-j4pr-qw6q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}