PT-2025-39468 · Yangzongzhuan · Ruoyi

·

CVE-2025-10989

·

Published

2025-09-26

·

Updated

2025-09-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yangzongzhuan RuoYi versions up to 4.8.1
Description A security flaw exists in yangzongzhuan RuoYi. The issue involves improper authorization due to manipulation of the userIds argument in the file '/system/role/authUser/selectAll'. This allows for remote exploitation. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 4.8.1 should be used.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10989

Affected Products

Ruoyi