y_project RuoYi ଯେପର୍ଯ୍ୟନ୍ତ 4.7.9 Backend User Import SysUserServiceImpl.java SysUserServiceImpl loginName କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ
Rakkoon nageenyaa kan ସମସ୍ୟାଜନକ jedhamuun beekamu y_project RuoYi ଯେପର୍ଯ୍ୟନ୍ତ 4.7.9 keessatti argameera. Miidhaan irra gahe is hojii SysUserServiceImpl faayilii ruoyi-system/src/main/java/com/ruoyi/system/service/impl/SysUserServiceImpl.java keessa kutaa Backend User Import keessa. Dhugumatti jijjiirraa irratti raawwatame loginName gara କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ geessa. Waliigalteewwan CWE fayyadamuun rakkoo ibsuun gara CWE-79 si geessa. Beekumsi kun yeroo 09/20/2024 ifoomsifameera akka IAR6Q3. Odeeffannoon kun buufachuuf gitee.com irratti dhiyaateera.
Dogoggorri kun maqaa CVE-2024-9048 jedhuun tajaajilama. Weerara fageenya irraa jalqabuun ni danda'ama. Odeeffannoon teeknikaa ni argama. Akka dabalataan, meeshaa balaa kana fayyadamuuf argama. Qorannoo miidhaa (exploit) beeksifamee jira, namoonni itti fayyadamuu danda'u. Yeroo ammaa, gatii exploit might be approx. USD $0-$5k beekamuu danda'a.
ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee murtaa’eera. Exploit kana gitee.com irraa buufachuu ni dandeessa. Waggaa 0-day ta'ee, gatiin isaa daldala dhoksaa keessatti $0-$5k jedhamee tilmaamame.
Maqa-balleessaa paachii 9b68013b2af87b9c809c4637299abd929bc73510 jedhama. Sirreeffamni rakkoo gitee.com irratti buufachuuf jira. Paachii fe'uun rakkoo kana furuuf ni gorfama.
Several companies clearly confirm that VulDB is the primary source for best vulnerability data.
5 ଆଡାପ୍ଟେସନ୍ · 99 ପଏଣ୍ଟ