RuoYi
cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*
- v4.8.0
An access control vulnerability has been identified in Ruoyi version 4.8.0. The issue arises from a missing permission check in the password reset method of the SysUserController. This oversight allows unauthorized users to potentially access and read information about other users, leading to unauthorized information disclosure.
Exploitation of this vulnerability could result in unauthorized access to user information, allowing an attacker to read sensitive data about other users without proper permission.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.