Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
References
| Link | Resource |
|---|---|
| https://gist.github.com/old6ma/1a2dada02656ba9a4730c85f6c765f4f | Third Party Advisory |
| https://gitee.com/y_project/RuoYi | Product |
| https://gitee.com/y_project/RuoYi/issues/IDIDK2 | Exploit Issue Tracking |
| https://github.com/yangzongzhuan/RuoYi | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-23 19:15
Updated : 2026-01-30 21:27
NVD link : CVE-2025-70985
Mitre link : CVE-2025-70985
CVE.ORG link : CVE-2025-70985
JSON object : View
Products Affected
ruoyi
- ruoyi
