CVE-2025-28403: High severity ruoyi ruoyi-cloud vulnerability
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28403?
CVE-2025-28403 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-28403?
To mitigate CVE-2025-28403, ensure that strict validation of user privileges is implemented in the editSave method.
Who is affected by CVE-2025-28403?
CVE-2025-28403 affects versions of RUoYi prior to 4.8.1, specifically version 4.8.0.
What type of attack does CVE-2025-28403 enable?
CVE-2025-28403 allows remote attackers to escalate privileges and modify system configuration settings.
Is there any workaround for CVE-2025-28403?
Currently, the recommended workaround for CVE-2025-28403 is to restrict access to the editSave method until a patch is applied.