CVE-2025-28409: High severity ruoyi ruoyi-cloud vulnerability
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28409?
CVE-2025-28409 is classified as a security vulnerability due to its potential to allow remote attackers to escalate privileges.
How do I fix CVE-2025-28409?
To fix CVE-2025-28409, ensure that proper permission checks are implemented in the add method of the /add/{parentId} endpoint.
What versions of RUoYi are affected by CVE-2025-28409?
CVE-2025-28409 specifically affects RUoYi version 4.8.0.
Can CVE-2025-28409 allow unauthorized access to sensitive features?
Yes, CVE-2025-28409 can allow unauthorized users to gain access and manipulate menu items under specified parent IDs.
Is there a known exploit for CVE-2025-28409?
While details on specific exploits may vary, the vulnerability allows for possible privilege escalation which can be exploited by attackers.