CVE-2025-46175 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
High CVSS: 7.5

CVE-2025-46175

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
Vendor
Ruoyi
Product
Ruoyi
CWE
CWE-862
Yayın Tarihi
2025-11-26 17:15:45
Güncelleme
2025-12-04 17:15:54
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar