CVE-2025-10218

Source
https://cve.org/CVERecord?id=CVE-2025-10218
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10218.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-10218
Published
2025-09-10T21:32:05Z
Modified
2026-08-12T03:51:31Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
lostvip-com ruoyi-go Background Management SysRoleDao.go SelectListPage sql injection
Details

A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the component Background Management Page. This manipulation of the argument sortName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10218.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.1"
                },
                {
                    "last_affected": "2.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/lostvip-com/ruoyi-go

Affected ranges

Type
GIT
Repo
https://github.com/lostvip-com/ruoyi-go
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:lostvip:ruoyi-go:2.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.1"
        },
        {
            "last_affected": "2.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10218.json"