PT-2025-37394 · Yangzongzhuan · Ruoyi

Aibot88

·

Published

2025-09-13

·

Updated

2025-10-10

·

CVE-2025-10384

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: yangzongzhuan RuoYi versions up to 4.8.1
Description: A flaw exists in yangzongzhuan RuoYi up to version 4.8.1 related to improper authorization within the Role Handler component. The issue is associated with the /system/role/authUser/cancelAll file. Manipulation of the roleId/userIds argument can lead to unauthorized access. The vulnerability is remotely exploitable.
Recommendations: Versions prior to 4.8.1 should be used.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10384

Affected Products

Ruoyi