PT-2025-20659 · Yangzongzhuan · Ruoyi-Vue
S0L42
·
Published
2025-05-11
·
Updated
2025-05-11
·
CVE-2025-4537
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RuoYi-Vue versions up to 3.8.9
Description
A problem was found in the Password Handler component, affecting some unknown functionality of the files ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue. This issue leads to cleartext storage of sensitive information in a cookie. The attack can be launched remotely, and the complexity of the attack is rather high. The exploitation is known to be difficult.
Recommendations
For versions up to 3.8.9, consider disabling the functionality related to the files ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue of the Password Handler component as a temporary workaround until a patch is available. Restrict access to sensitive information stored in cookies to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi-Vue