References https://tttang.com/archive/1712/ https://www.cnblogs.com/backlion/p/18896463 https://zhuanlan.zhihu.com/p/25211039925 https://github.com/ax1sX/SecurityList/blob/main/Java_OA/RuoYi.md https://sp4zcmd.github.io/2021/08/30/%E8%8B%A5%E4%BE%9Dcms%E5%90%8E%E5%8F%B0%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90/ https://www.cnblogs.com/pursue-security/p/17658404.html https://doc.ruoyi.vip/ruoyi/document/kslj.html https://blog.csdn.net/weixin_45055749/article/details/139200634 https://www.ihonker.com/thread-33318-1-1.html https://www.secpulse.com/archives/205550.html
Related VulnerabilitiesRuoYi AI /prod-api/system/model/list 信息泄露漏洞(CVE-2025-3199)(CVE-2025-7901)RuoYi Swagger UI组件configUrl参数跨站脚本漏洞PoCCNVD-2021-01931: Ruoyi Management System - Local File InclusionPoCruoyi-druid-unauth: 若依管理系统未授权访问RuoYi-Vue-Plus sendMessageWithAttachment 任意文件读取漏洞RuoYi AI /prod-api/auth/login 默认口令漏洞(CVE-2025-3202) RuoYi-ai系统未授权访问漏洞ruoyi-vue-pro 路径遍历漏洞若依-RuoYi-Vue getUsersByPhone 未授权访问漏洞