ZeroHour

CVE-2022-23869

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p50
Published
()
Modified
Description

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

Vendors
ruoyi
Products
ruoyi
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.