PT-2025-20659 · Yangzongzhuan · Ruoyi-Vue

S0L42

·

Published

2025-05-11

·

Updated

2025-05-11

·

CVE-2025-4537

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions RuoYi-Vue versions up to 3.8.9
Description A problem was found in the Password Handler component, affecting some unknown functionality of the files ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue. This issue leads to cleartext storage of sensitive information in a cookie. The attack can be launched remotely, and the complexity of the attack is rather high. The exploitation is known to be difficult.
Recommendations For versions up to 3.8.9, consider disabling the functionality related to the files ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue of the Password Handler component as a temporary workaround until a patch is available. Restrict access to sensitive information stored in cookies to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-4537

Affected Products

Ruoyi-Vue