PT-2025-3443 · Ruoyi · Ruoyi

Published

2025-01-29

·

Updated

2025-05-14

·

CVE-2024-57436

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RuoYi version 4.8.0
Description The issue allows unauthorized attackers to view the session ID of the admin in the system monitoring, enabling them to impersonate Admin users via a crafted cookie.
Recommendations RuoYi version 4.8.0: Update the system to prevent session ID exposure and ensure proper cookie handling to mitigate admin impersonation risks.

Exploit

Fix

Information Disclosure

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-57436
GHSA-V664-QGX9-WF79

Affected Products

Ruoyi