Описание
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
Ссылки
- ExploitThird Party Advisory
- Product
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00295
Низкий
7.2 High
CVSS3
Дефекты
CWE-922
Связанные уязвимости
CVSS3: 7.2
github
около 1 года назад
RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
EPSS
Процентиль: 52%
0.00295
Низкий
7.2 High
CVSS3
Дефекты
CWE-922