NVD HIGH: CVE-2026-97324 — A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026....
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated
CVE-2026-97324