CVE-2025-10384: yangzongzhuan RuoYi Role cancelAll improper authorization
A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/cancelAll of the component Role Handler. Executing manipulation of the argument roleId/userIds can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10384?
CVE-2025-10384 has a moderate severity due to improper authorization that could be exploited.
How do I fix CVE-2025-10384?
To fix CVE-2025-10384, upgrade yangzongzhuan RuoYi to version 4.8.2 or later.
What components are affected by CVE-2025-10384?
CVE-2025-10384 affects the Role Handler component specifically in the file /system/role/authUser/cancelAll.
Can CVE-2025-10384 lead to unauthorized access?
Yes, CVE-2025-10384 can lead to unauthorized access due to improper handling of roleId/userIds.
Is CVE-2025-10384 specific to certain user roles?
CVE-2025-10384 is not specific to any user role and can affect all users if exploited.