An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.
| Software | From | Fixed in |
|---|---|---|
| ruoyi / ruoyi | - | 4.7.3.x |
com.ruoyi / ruoyi
|
- | 4.7.4 |