CNNVD-202508-2926 Information
Aug 25, 2025
cve
CNNVD ID
CNNVD-202508-2926
Related CVE
- CNNVD Published: 2025-08-25
Description (Chinese)
ruoyi-go是lostvip.com个人开发者的一个后台管理系统。 ruoyi-go 2.1及之前版本存在安全漏洞,该漏洞源于对文件modules/system/system_router.go中参数orderByColumn/isAsc的错误操作导致SQL注入。
Description (English)
Ruoyi-go is a back-office management system for individual developers in lostvip.com. The security gap in the ruoyi-go 2.1 and earlier versions stems from the mishandling of the argument in document Modeules/system/system router.go which led to the injection of SQL.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
个人开发者
Published
2025-08-25
Last Modified
2026-02-24
References
https://vuldb.com/?submit.633731 https://vuldb.com/?submit.633730 https://vuldb.com/?id.321254 https://vuldb.com/?ctiid.321254 https://github.com/on-theway/cve/issues/9 https://github.com/on-theway/cve/issues/8 https://nvd.nist.gov/vuln/detail/CVE-2025-9413
Share on: