CyberRota Analysis
AI-GeneratedRuoYi-Vue-Plus version 6.0.0 is vulnerable due to a flaw in the FlwTaskController.java component, which allows remote attackers to execute arbitrary code through specific service methods and POST requests. This vulnerability poses a significant risk to applications utilizing this framework, as it can lead to unauthorized access and control over the affected systems. Organizations using RuoYi-Vue-Plus should prioritize patching or mitigating this vulnerability to safeguard their environments against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components