PT-2025-14829 · Ruoyi-Ai · Ruoyi-Ai

Tr0E

·

Published

2025-04-04

·

Updated

2025-04-09

·

CVE-2025-3202

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ageerle ruoyi-ai versions up to 2.0.0
Description A critical vulnerability has been found, affecting an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. This leads to improper authorization and can be exploited remotely. The exploit has been disclosed publicly.
Recommendations For versions up to 2.0.0, upgrade to version 2.0.1 to address this issue.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-3202

Affected Products

Ruoyi-Ai