RUoYi Privilege Escalation Vulnerability in SysDictTypeController Component

Vulnerability

A privilege escalation vulnerability has been identified in RUoYi version 4.8.0. The issue arises in the SysDictTypeController component, where a remote attacker can exploit inadequate access controls to escalate privileges. This vulnerability allows unauthorized users to modify dictionary records that may contain sensitive information such as user roles and permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in user roles and permissions, allowing attackers to gain elevated privileges and manipulate system settings or behaviors.

Reproduction

To reproduce this vulnerability, a normal user must access the '/editSave' method in the 'SysDictTypeController' component. Once there, the user can send a request to modify dictionary records. The lack of proper permission checks enables unauthorized users to alter data that could impact user roles and system configurations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.