PT-2025-3443 · Ruoyi · Ruoyi
Published
2025-01-29
·
Updated
2025-05-14
·
CVE-2024-57436
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RuoYi version 4.8.0
Description
The issue allows unauthorized attackers to view the session ID of the admin in the system monitoring, enabling them to impersonate Admin users via a crafted cookie.
Recommendations
RuoYi version 4.8.0: Update the system to prevent session ID exposure and ensure proper cookie handling to mitigate admin impersonation risks.
Exploit
Fix
Information Disclosure
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi