yeqifu warehouse Vertical Privilege Escalation Vulnerability

Vulnerability

A vertical privilege escalation vulnerability exists in yeqifu warehouse versions up to aaf29962ba407d22d991781de28796ee7b4670e4. The issue is located in the UserController.java file, specifically within the saveUserRole function. This vulnerability arises from improper authorization checks, allowing ordinary users to assign themselves administrative roles. The flaw can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows users to gain unauthorized administrative privileges, enabling them to access and modify system settings and data with full administrative rights.

Reproduction

To reproduce this vulnerability, log in as a regular user and send a POST request to the /user/saveUserRole endpoint. Include the uid parameter to specify the user account and the ids parameter to indicate the role being assigned, such as the system administrator role.

Added: Jan 4, 2026, 2:17 AM
Updated: Jan 4, 2026, 2:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.