RUoYi Privilege Escalation Vulnerability in cancelAuthUserAll Method
Vulnerability
A privilege escalation vulnerability exists in RUoYi version 4.8.0. The issue arises in the cancelAuthUserAll method, which fails to properly verify whether the user making the request has administrative rights. This flaw allows remote attackers to escalate privileges.
Impact
Exploitation of this vulnerability could lead to unauthorized administrative access, allowing attackers to gain elevated privileges within the application.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
6.6remediation
0.0relevance
0.0threat
6.4urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
