Description
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0165 | Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles. |
Github GHSA |
GHSA-h5jh-rp76-q242 | RuoYi has insecure permissions |
References
History
Wed, 14 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruoyi
Ruoyi ruoyi |
|
| CPEs | cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ruoyi
Ruoyi ruoyi |
Thu, 06 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jan 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-06T15:33:47.497Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57438
Updated: 2025-01-29T15:12:04.720Z
Status : Analyzed
Published: 2025-01-29T15:15:17.283
Modified: 2025-05-14T18:26:41.480
Link: CVE-2024-57438
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA