Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rvvc-m8pv-rj9r

Опубликовано: 07 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

EPSS

Процентиль: 74%
0.00848
Низкий

7.2 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.2
nvd
10 месяцев назад

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

EPSS

Процентиль: 74%
0.00848
Низкий

7.2 High

CVSS3

Дефекты

CWE-284