An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/yangzongzhuan/RuoYi | product |
https://github.com/20210607/cve_public/blob/main/ruoyi_case/CVE-2025-28403.md | third party advisory exploit |