Skip to main content

CVE-2025-8847: Ruoyi RuoYi XSS Vulnerability

CVE-2025-8847 is a cross-site scripting flaw in Ruoyi RuoYi affecting versions up to 4.8.1 through the notice edit function. Attackers can exploit this remotely via malicious input. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-8847 Overview

CVE-2025-8847 is a stored cross-site scripting (XSS) vulnerability in the RuoYi web application framework, affecting versions up to 4.8.1. The flaw resides in the Edit function handling the /system/notice/edit endpoint. Attackers can inject malicious script content through the noticeTitle or noticeContent parameters. The exploit requires authenticated access with low privileges and user interaction to trigger. Public disclosure has occurred through GitHub and VulDB references, though no active exploitation has been observed. RuoYi is a widely-deployed Java-based rapid development framework used across Chinese enterprise environments, making this notice module a viable vector for internal phishing and session hijacking against administrative users.

Critical Impact

Authenticated attackers can inject persistent JavaScript payloads into notice records, executing arbitrary script in the browser context of any administrator or user viewing the affected notice.

Affected Products

  • RuoYi versions up to and including 4.8.1
  • yangzongzhuan/RuoYi GitHub repository builds
  • Deployments exposing the /system/notice/edit endpoint

Discovery Timeline

  • 2025-08-11 - CVE-2025-8847 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8847

Vulnerability Analysis

The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. The Edit function in the notice management module accepts user-supplied values for noticeTitle and noticeContent without proper output encoding or input sanitization. When an administrator or another user later renders the stored notice, the injected payload executes in their browser session.

Exploitation requires network access to the RuoYi backend, low-privileged authentication, and victim interaction such as viewing the notice list or detail page. The scope remains limited to the browser session of the affected user, but successful execution can lead to session token theft, forced administrative actions, or delivery of secondary payloads within the trusted application origin.

Root Cause

The root cause is missing server-side and client-side sanitization of the noticeTitle and noticeContent parameters submitted to /system/notice/edit. The application persists raw HTML and JavaScript into the notice record and later reflects it into rendered pages without contextual encoding. Framework-provided escape utilities such as HTML entity encoding are not applied at the rendering layer.

Attack Vector

An authenticated attacker with permission to create or edit system notices sends a crafted POST request to /system/notice/edit containing a JavaScript payload inside the noticeTitle or noticeContent field. The payload is stored in the notice table. When any user with access to the notice module views the notice, the injected script executes under the RuoYi application origin.

Because the payload persists server-side, a single injection can affect multiple victims over time. Typical payloads target administrator session cookies, CSRF tokens, or invoke administrative API endpoints on behalf of the victim. See the GitHub Issue Discussion for reproduction details published by the reporter.

Detection Methods for CVE-2025-8847

Indicators of Compromise

  • Notice records in the RuoYi database containing HTML tags such as <script>, <img onerror=>, or <svg onload=> within notice_title or notice_content columns
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after viewing the notice module
  • HTTP POST requests to /system/notice/edit originating from low-privileged accounts containing script-like payloads in parameters

Detection Strategies

  • Inspect web server access logs for POST requests to /system/notice/edit where request bodies contain angle-bracket characters, javascript: URIs, or common XSS keywords
  • Perform database audits of the sys_notice table to identify stored payloads containing executable HTML or JavaScript
  • Deploy a Web Application Firewall (WAF) rule set that flags XSS signatures against RuoYi notice endpoints

Monitoring Recommendations

  • Enable application-level logging of all notice create and edit actions with full parameter capture for forensic review
  • Monitor administrator accounts for anomalous session activity following interaction with notice pages, including new user creation or privilege changes
  • Alert on Content Security Policy (CSP) violation reports if CSP headers are deployed in report-only or enforcing mode

How to Mitigate CVE-2025-8847

Immediate Actions Required

  • Restrict access to the /system/notice/edit endpoint to a minimal set of trusted administrative accounts until a patched build is deployed
  • Audit and sanitize existing entries in the sys_notice table, removing any records containing HTML or script content
  • Deploy a WAF signature to block requests to notice endpoints containing common XSS payload patterns

Patch Information

At the time of publication, no official patched release has been referenced in the NVD entry. Track the upstream project through the GitHub Issue Discussion and VulDB #319381 for remediation updates. Operators maintaining forks should apply server-side HTML entity encoding to noticeTitle and noticeContent and enforce output escaping in the notice rendering templates.

Workarounds

  • Apply strict server-side input validation rejecting angle brackets and script-related keywords in notice parameters
  • Deploy a Content Security Policy that disables inline script execution and restricts script sources to trusted origins
  • Use HTML entity encoding on the notice rendering templates such that stored HTML is displayed as literal text rather than executed markup
bash
# Example nginx WAF-style rule to block script payloads on notice edit
location /system/notice/edit {
    if ($request_body ~* "(<script|onerror=|javascript:|<svg)") {
        return 403;
    }
    proxy_pass http://ruoyi_backend;
}

# Example Content Security Policy header
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'" always;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.