Access Control Vulnerability in RuoYi v4.8.2 by Yangzongzhuan
CVE-2025-70986
7.5HIGH
What is CVE-2025-70986?
A security flaw exists in the selectDept function of RuoYi v4.8.2, enabling unauthorized attackers to bypass access controls and gain access to sensitive department data. This vulnerability poses a significant risk, as it can lead to data leaks and compromise overall system integrity. It is crucial for users and administrators of RuoYi to apply necessary security measures and updates to safeguard against potential exploitation. For more information, you can refer to the official repositories and discussions available on GitHub and Gitee.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
