{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ruoyi-vue-pro--2026.08/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yunaiv:ruoyi_vue_pro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-97324"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ruoyi-vue-pro (\u003c= 2026.08)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["YunaiV"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-97324) exists in the ruoyi-vue-pro platform, specifically within the Demo-order Payment Callback Handler. The flaw is located in the \u003ccode\u003eupdateDemoOrderPaid\u003c/code\u003e function within the \u003ccode\u003ePayDemoOrderController.java\u003c/code\u003e file. An attacker can perform remote exploitation by manipulating the \u003ccode\u003eID\u003c/code\u003e argument, leading to improper authorization. This vulnerability allows an unauthenticated or unauthorized user to interact with the payment callback logic, potentially forcing state changes in payment records. Given that functional exploit code is publicly available, organizations running versions of ruoyi-vue-pro up to 2026.08 are at risk. The vendor has not provided a patch as of the disclosure date, necessitating immediate compensatory controls at the network or application perimeter to prevent unauthorized access to these sensitive callback endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthorized party to manipulate the state of demo payment orders. In a production environment, if this handler is repurposed or exposed, it could lead to logical failures in payment processing, financial data inconsistency, and potential unauthorized state modifications that may impact business operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict IP allowlisting for the application’s administrative and callback endpoints to mitigate remote access.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to monitor for suspicious or unexpected \u003ccode\u003eID\u003c/code\u003e parameter values targeting the \u003ccode\u003e/admin/demo/pay\u003c/code\u003e URI patterns.\u003c/li\u003e\n\u003cli\u003eReview all custom modifications to \u003ccode\u003ePayDemoOrderController.java\u003c/code\u003e to ensure input validation and authorization checks are enforced before updating order records.\u003c/li\u003e\n\u003cli\u003eRestrict internet exposure of the ruoyi-vue-pro admin interfaces if not required for business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:47:48Z","date_published":"2026-09-24T20:47:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ruoyi-vue-pro-auth-bypass/","summary":"A remote authorization bypass in the ruoyi-vue-pro payment callback handler allows unauthorized manipulation of payment order states via the ID argument.","title":"Improper Authorization Vulnerability in ruoyi-vue-pro","url":"https://feed.craftedsignal.io/briefs/2026-09-ruoyi-vue-pro-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ruoyi-Vue-Pro (\u003c= 2026.08)","version":"https://jsonfeed.org/version/1.1"}