References https://zhuanlan.zhihu.com/p/700105607 https://www.cnblogs.com/backlion/p/18896463 https://blog.csdn.net/qq_41901122/article/details/127795680 https://gitee.com/y_project/RuoYi/issues/I7MOWG https://bbs.huaweicloud.com/blogs/399830 https://www.secpulse.com/archives/205550.html https://cloud.tencent.com/developer/article/2513145 https://threedr3am.github.io/2021/04/25/3.0.12%E7%89%88%E6%9C%AC%20Tmymeleaf%20RCE%E7%9A%84%E7%BB%88%E7%BB%93%EF%BC%9F%EF%BC%88%E8%8B%A5%E4%BE%9Druoyi%E6%9C%80%E6%96%B0%E7%89%88%E6%9C%AC%E5%90%8E%E5%8F%B0RCE%EF%BC%89/ https://zhuanlan.zhihu.com/p/1968704975916996046 https://cn-sec.com/archives/2616571.html https://blog.csdn.net/qq_32808455/article/details/135579745 https://cloud.tencent.com/developer/article/2457613 https://cn-sec.com/archives/1139767.html https://www.cnblogs.com/pursue-security/p/17658404.html https://blog.csdn.net/zkaqlaoniao/article/details/135057047 https://blog.csdn.net/jwt8token/article/details/155651041 https://www.cnblogs.com/hetianlab/p/18215920 https://threedr3am.github.io/2021/04/26/3.0.12%20Thymeleaf%20RCE%20Bypass%EF%BC%88%E8%8B%A5%E4%BE%9Druoyi%E6%9C%80%E6%96%B0%E7%89%88%E6%9C%AC%E5%90%8E%E5%8F%B0RCE%EF%BC%89/ https://blog.csdn.net/2401_89199642/article/details/143994088 https://developer.volcengine.com/articles/7381299490848210981
Related Vulnerabilities若依管理系统 /monitor/cache/getNames 命令执行漏洞PoCthymeleaf-oob: Thymeleaf - Out of Band Template Injection若依后台管理系统 XML外部实体注入漏洞若依RuoYi druid组件弱口令漏洞若依RuoYi /system/role/export接口 SQL注入漏洞若依RuoYi /system/dept/edit接口 SQL注入漏洞若依后台管理系统 invoke_target 代码注入漏洞若依后台管理系统 CVE-2023-49371 SQL注入漏洞若依管理系统任意文件下载漏洞若依管理系统 后台定时任务 远程代码执行漏洞若依管理系统 弱口令漏洞若依-管理系统任意文件上传(CVE-2022-32065)