VulnerabilityAnalyzed
CVE-2025-10218
This manipulation of the argument sortName causes sql injection.
LOW 2.1EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the component Background Management Page. This manipulation of the argument sortName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- lostvip/ruoyi-go
- Source
- cna@vuldb.com
References
- https://github.com/on-theway/cve/issues/10Broken Link
- https://vuldb.com/?ctiid.323486Permissions Required, VDB Entry
- https://vuldb.com/?id.323486Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.641027Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.