PT-2025-39468 · Yangzongzhuan · Ruoyi

Aibot888

·

Published

2025-09-26

·

Updated

2025-09-26

·

CVE-2025-10989

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yangzongzhuan RuoYi versions up to 4.8.1
Description A security flaw exists in yangzongzhuan RuoYi. The issue involves improper authorization due to manipulation of the userIds argument in the file '/system/role/authUser/selectAll'. This allows for remote exploitation. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 4.8.1 should be used.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10989

Affected Products

Ruoyi