ZeroHour

CVE-2025-70985

PoC
CVSS 3.1
9.1 critical
EPSS
<1%p33
Published
()
Modified
Description

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

Vendors
ruoyi
Products
ruoyi
Weakness
CWE-284, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.