CVE-2025-28410: Critical severity ruoyi ruoyi-cloud vulnerability
Published Apr 7, 2025
·Updated
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Affected Software
2 affected components
Ruoyi Ruoyi
Ruoyi Ruoyi=4.8.0
Event History
Apr 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28410?
CVE-2025-28410 is classified as a high-severity vulnerability due to the ability of a remote attacker to escalate privileges.
2
How do I fix CVE-2025-28410?
To fix CVE-2025-28410, ensure that proper validation is in place for the cancelAuthUserAll method to check for administrative privileges.
3
Which versions of RUoYi are affected by CVE-2025-28410?
CVE-2025-28410 affects version 4.8.0 of RUoYi.
4
Can CVE-2025-28410 be exploited remotely?
Yes, CVE-2025-28410 can be exploited remotely by an attacker without authenticated access.
5
What type of vulnerability is CVE-2025-28410?
CVE-2025-28410 is a privilege escalation vulnerability that allows unauthorized access to administrative functionalities.