CVE-2025-8847 | yangzongzhuan RuoYi up to 4.8.1 /system/notice/edit noticeTitle/noticeContent cross site scripting (Issue 298)
A vulnerability described as problematic has been identified in yangzongzhuan RuoYi up to 4.8.1. The affected element is the function Edit of the file /system/notice/edit. The manipulation of the argument noticeTitle/noticeContent results in cross site scripting.
This vulnerability is known as CVE-2025-8847. It is possible to launch the attack remotely. Furthermore, an exploit is available.