PT-2025-3445 · Ruoyi · Ruoyi

Published

2025-01-29

·

Updated

2025-05-14

·

CVE-2024-57438

CVSS v4.0

5.6

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions RuoYi version 4.8.0
Description The issue concerns insecure permissions that allow authenticated attackers to escalate privileges by assigning themselves higher level roles.
Recommendations For RuoYi version 4.8.0, update the permissions to restrict role assignments and prevent privilege escalation. Ensure that only authorized users can assign roles to prevent abuse.

Exploit

Fix

Incorrect Authorization

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-57438
GHSA-H5JH-RP76-Q242

Affected Products

Ruoyi