PT-2025-3446 · Ruoyi · Ruoyi
Published
2025-01-29
·
Updated
2025-01-29
·
CVE-2024-57439
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ruoyi version 4.8.0
Description
The issue is related to the reset password interface, where attackers with Admin privileges can cause a Denial of Service (DoS) by duplicating the
login name of the account.Recommendations
ruoyi version 4.8.0: Update the reset password interface to prevent duplication of the
login name and ensure proper validation to mitigate the Denial of Service (DoS) risk.Exploit
Fix
DoS
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruoyi