Privilege Escalation Vulnerability in RUoYi v.4.8.0 by YangZongzhuan
CVE-2025-28401

6.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 April 2025

What is CVE-2025-28401?

A vulnerability has been identified in RUoYi version 4.8.0, allowing remote attackers to escalate their privileges by manipulating the menuId parameter. This issue enables unauthorized users to potentially gain access to restricted functionalities within the application, thereby raising serious security concerns. It is crucial for users and system administrators to apply the necessary patches and mitigations to ensure the integrity and security of their systems.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-28401 : Privilege Escalation Vulnerability in RUoYi v.4.8.0 by YangZongzhuan