CVE-2025-2744 | zhijiantianya ruoyi-vue-pro 2.4.1 Material Upload Interface upload-news-image File path traversal
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the argument File leads to path traversal.
This vulnerability is traded as CVE-2025-2744. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.