PT-2025-15239 · Ruoyi · Ruoyi

Published

2025-04-07

·

Updated

2025-04-09

·

CVE-2025-28401

CVSS v3.1

6.7

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions RUoYi version 4.8.0
Description The issue allows a remote attacker to escalate privileges via the menuId parameter.
Recommendations For RUoYi version 4.8.0, avoid using the menuId parameter until the issue is resolved.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-28401

Affected Products

Ruoyi