CVE-2025-8847 Overview
CVE-2025-8847 is a stored cross-site scripting (XSS) vulnerability in the RuoYi web application framework, affecting versions up to 4.8.1. The flaw resides in the Edit function handling the /system/notice/edit endpoint. Attackers can inject malicious script content through the noticeTitle or noticeContent parameters. The exploit requires authenticated access with low privileges and user interaction to trigger. Public disclosure has occurred through GitHub and VulDB references, though no active exploitation has been observed. RuoYi is a widely-deployed Java-based rapid development framework used across Chinese enterprise environments, making this notice module a viable vector for internal phishing and session hijacking against administrative users.
Critical Impact
Authenticated attackers can inject persistent JavaScript payloads into notice records, executing arbitrary script in the browser context of any administrator or user viewing the affected notice.
Affected Products
- RuoYi versions up to and including 4.8.1
- yangzongzhuan/RuoYi GitHub repository builds
- Deployments exposing the /system/notice/edit endpoint
Discovery Timeline
- 2025-08-11 - CVE-2025-8847 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8847
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. The Edit function in the notice management module accepts user-supplied values for noticeTitle and noticeContent without proper output encoding or input sanitization. When an administrator or another user later renders the stored notice, the injected payload executes in their browser session.
Exploitation requires network access to the RuoYi backend, low-privileged authentication, and victim interaction such as viewing the notice list or detail page. The scope remains limited to the browser session of the affected user, but successful execution can lead to session token theft, forced administrative actions, or delivery of secondary payloads within the trusted application origin.
Root Cause
The root cause is missing server-side and client-side sanitization of the noticeTitle and noticeContent parameters submitted to /system/notice/edit. The application persists raw HTML and JavaScript into the notice record and later reflects it into rendered pages without contextual encoding. Framework-provided escape utilities such as HTML entity encoding are not applied at the rendering layer.
Attack Vector
An authenticated attacker with permission to create or edit system notices sends a crafted POST request to /system/notice/edit containing a JavaScript payload inside the noticeTitle or noticeContent field. The payload is stored in the notice table. When any user with access to the notice module views the notice, the injected script executes under the RuoYi application origin.
Because the payload persists server-side, a single injection can affect multiple victims over time. Typical payloads target administrator session cookies, CSRF tokens, or invoke administrative API endpoints on behalf of the victim. See the GitHub Issue Discussion for reproduction details published by the reporter.
Detection Methods for CVE-2025-8847
Indicators of Compromise
- Notice records in the RuoYi database containing HTML tags such as <script>, <img onerror=>, or <svg onload=> within notice_title or notice_content columns
- Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after viewing the notice module
- HTTP POST requests to /system/notice/edit originating from low-privileged accounts containing script-like payloads in parameters
Detection Strategies
- Inspect web server access logs for POST requests to /system/notice/edit where request bodies contain angle-bracket characters, javascript: URIs, or common XSS keywords
- Perform database audits of the sys_notice table to identify stored payloads containing executable HTML or JavaScript
- Deploy a Web Application Firewall (WAF) rule set that flags XSS signatures against RuoYi notice endpoints
Monitoring Recommendations
- Enable application-level logging of all notice create and edit actions with full parameter capture for forensic review
- Monitor administrator accounts for anomalous session activity following interaction with notice pages, including new user creation or privilege changes
- Alert on Content Security Policy (CSP) violation reports if CSP headers are deployed in report-only or enforcing mode
How to Mitigate CVE-2025-8847
Immediate Actions Required
- Restrict access to the /system/notice/edit endpoint to a minimal set of trusted administrative accounts until a patched build is deployed
- Audit and sanitize existing entries in the sys_notice table, removing any records containing HTML or script content
- Deploy a WAF signature to block requests to notice endpoints containing common XSS payload patterns
Patch Information
At the time of publication, no official patched release has been referenced in the NVD entry. Track the upstream project through the GitHub Issue Discussion and VulDB #319381 for remediation updates. Operators maintaining forks should apply server-side HTML entity encoding to noticeTitle and noticeContent and enforce output escaping in the notice rendering templates.
Workarounds
- Apply strict server-side input validation rejecting angle brackets and script-related keywords in notice parameters
- Deploy a Content Security Policy that disables inline script execution and restricts script sources to trusted origins
- Use HTML entity encoding on the notice rendering templates such that stored HTML is displayed as literal text rather than executed markup
# Example nginx WAF-style rule to block script payloads on notice edit
location /system/notice/edit {
if ($request_body ~* "(<script|onerror=|javascript:|<svg)") {
return 403;
}
proxy_pass http://ruoyi_backend;
}
# Example Content Security Policy header
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
