CVE-2026-97324
7.3 HIGHPublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-266, CWE-285
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-102293PoC
- MEDIUMCVE-2026-102846PoC
- LOWCVE-2026-18817PoC
- MEDIUMCVE-2026-93961PoC
- HIGHCVE-2026-96556PoC
- MEDIUMCVE-2026-96880PoC
- MEDIUMCVE-2026-96881PoC
- MEDIUMCVE-2026-96882PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.