CVE-2025-28411: Critical severity ruoyi ruoyi-cloud vulnerability
Published Apr 7, 2025
·Updated
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Affected Software
2 affected components
Ruoyi Ruoyi
Ruoyi Ruoyi=4.8.0
Event History
Apr 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28411?
CVE-2025-28411 has a critical severity rating due to its potential to allow remote privilege escalation.
2
How do I fix CVE-2025-28411?
To fix CVE-2025-28411, update RUoYi to the patched version or apply the recommended security patches.
3
What is the attack vector for CVE-2025-28411?
CVE-2025-28411 can be exploited remotely through the editSave method in the /tool/gen/editSave endpoint.
4
What versions of RUoYi are affected by CVE-2025-28411?
CVE-2025-28411 specifically affects RUoYi version 4.8.0.
5
Are there any known exploits for CVE-2025-28411?
Yes, CVE-2025-28411 has known exploits that can leverage the vulnerability to escalate user privileges.