CVE-2026-97324
🟡 Monitoruj
Nieprawidłowa autoryzacja w YunaiV/zhijiantianya umożliwia zdalne manipulowanie zamówieniami.
CVSS
7.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-09-24 20:17:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 16:17:18 UTC |