RUoYi Privilege Escalation Vulnerability in cancelAuthUserAll Method

Vulnerability

A privilege escalation vulnerability exists in RUoYi version 4.8.0. The issue arises in the cancelAuthUserAll method, which fails to properly verify whether the user making the request has administrative rights. This flaw allows remote attackers to escalate privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative access, allowing attackers to gain elevated privileges within the application.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.