CVE-2026-97324

🟡 Monitoruj

Nieprawidłowa autoryzacja w YunaiV/zhijiantianya umożliwia zdalne manipulowanie zamówieniami.

CVSS
7.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-24 20:17:35 UTC
Ostatnia modyfikacja (NVD)2026-10-05 16:17:18 UTC
Referencje