RuoYi Password Reset Interface Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the password reset interface of RuoYi version 4.8.0. This issue allows attackers with admin privileges to duplicate the login name of any user account, including the admin account. The duplication of the login name prevents the user from logging in, effectively causing a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, where the affected user, including admin users, is unable to log in to the system.

Reproduction

To reproduce this vulnerability, an attacker must log into the RuoYi system with admin privileges. Once logged in, the attacker can navigate to the password reset interface and initiate a password reset for any user account. During this process, the attacker can overwrite the original login name with a duplicate, effectively causing the original login name to be invalidated. After the login name is duplicated, the attacker can attempt to log in as the admin user, but the login will fail, demonstrating the denial-of-service condition.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
6.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.