CVE-2024-6511
Last modified
CVE-2024-6511 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type Handler. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type Handler. The manipulation of the argument HttpHeaders.CONTENT_TYPE leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270343.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruoyi | Ruoyi | <= 4.7.9 |
References
- https://gitee.com/y_project/RuoYi/issues/IA8O7OExploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.270343Permissions Required, VDB Entry
- https://vuldb.com/?id.270343Third Party Advisory, VDB Entry
- https://gitee.com/y_project/RuoYi/issues/IA8O7OExploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.270343Permissions Required, VDB Entry
- https://vuldb.com/?id.270343Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6511?
How severe is CVE-2024-6511?
How do I fix CVE-2024-6511?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6505A flaw was found in the virtio-net device in QEMU. When enab…6.8
- CVE-2024-6506Information exposure vulnerability in the MRW plugin, in its…8.2
- CVE-2024-6507Command injection when ingesting a remote Kaggle dataset due…8.1
- CVE-2024-6508An insufficient entropy vulnerability was found in the Opens…8
- CVE-2024-6509Marinus Pfund, member of the AXIS OS Bug Bounty Program, ha…6.5
- CVE-2024-6510Local Privilege Escalation in AVG Internet Security v24 on W…7.8
- CVE-2024-6512Authorization bypass in the PAM access request approval mech…6.5
- CVE-2024-6513Rejected reason: CVE assigned by mistake as a duplicate.
- CVE-2024-6515Web browser interface may manipulate application username/pa…8.1
- CVE-2024-6516Cross Site Scripting vulnerabilities where found providing a…6.1
- CVE-2024-6517The Contact Form 7 Math Captcha WordPress plugin through 2.0…6.1
- CVE-2024-6518The Contact Form Plugin by Fluent Forms for Quiz, Survey, an…4.4
Are you affected by CVE-2024-6511?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
