yangzongzhuan/RuoYi
cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*
- 4.8.0
A privilege escalation vulnerability exists in RUoYi version 4.8.0. The issue arises in the menu management feature, specifically within the 'add' method of the '/add/{parentId}' endpoint'. The vulnerability allows remote attackers to escalate privileges by exploiting inadequate validation of user permissions when adding menu items under a specified parent ID.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing users to gain elevated rights or access within the application.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.