ZeroHour

CVE-2025-28403

PoC
CVSS 3.1
7.2 high
EPSS
<1%p48
Published
()
Modified
Description

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

Vendors
ruoyi
Products
ruoyi
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.