Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
The data update function in RuoYi v4.8.2 does not properly verify whether the requesting user has permissions to modify the specified resources. An unauthenticated attacker can send a properly crafted request to the update endpoint, bypassing access control mechanisms. As a result, it is possible to modify data belonging to other users or system resources to which the attacker should not have access.
An attacker can arbitrarily modify data beyond the scope of their permissions, which may lead to violation of data integrity stored in the system and potential takeover of control over resources of other users.
Patches available from the vendor should be applied according to references. It is recommended to monitor the official project repository on Gitee (https://gitee.com/y_project/RuoYi) and GitHub (https://github.com/yangzongzhuan/RuoYi) to obtain updates.
RuoYi v4.8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NRuoyi
APPRuoyi4.8.14.8.2
Related vulnerabilities
SQL Injection (RCE) w RuoYi v.4.7.9 i wcześniejszych — funkcja createTable
RuoYi 4.8.0 – privilege escalation przez metodę changeStatus
Eskalacja uprawnień przez parametr jobId w RuoYi v.4.8.0
Eskalacja uprawnień w RuoYi v.4.8.0 poprzez parametr jobLogId
RuoYi 4.8.0 — privilege escalation przez brak walidacji parametru deptId