icon

We found results for “

CVE-2024-57438

Date: January 28, 2025

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Default Permissions

CWE-276

Incorrect Authorization

CWE-863

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us