CRITICAL🇵🇱 Wersja polska

CVE-2025-70985

CVSS 9.1v3.1pub. 2026-01-23upd. 2026-01-30

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

🤖 AI Analysis
How it works

The data update function in RuoYi v4.8.2 does not properly verify whether the requesting user has permissions to modify the specified resources. An unauthenticated attacker can send a properly crafted request to the update endpoint, bypassing access control mechanisms. As a result, it is possible to modify data belonging to other users or system resources to which the attacker should not have access.

Impact

An attacker can arbitrarily modify data beyond the scope of their permissions, which may lead to violation of data integrity stored in the system and potential takeover of control over resources of other users.

Mitigation & patch

Patches available from the vendor should be applied according to references. It is recommended to monitor the official project repository on Gitee (https://gitee.com/y_project/RuoYi) and GitHub (https://github.com/yangzongzhuan/RuoYi) to obtain updates.

Who is affected

RuoYi v4.8.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Ruoyi

    APP
    Ruoyi
    4.8.14.8.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-57521CRITICAL10.0PL ✓same product

SQL Injection (RCE) w RuoYi v.4.7.9 i wcześniejszych — funkcja createTable

CVE-2025-28405CRITICAL9.8PL ✓same product

RuoYi 4.8.0 – privilege escalation przez metodę changeStatus

CVE-2025-28402CRITICAL9.8PL ✓same product

Eskalacja uprawnień przez parametr jobId w RuoYi v.4.8.0

CVE-2025-28406CRITICAL9.8PL ✓same product

Eskalacja uprawnień w RuoYi v.4.8.0 poprzez parametr jobLogId

CVE-2025-28408CRITICAL9.8PL ✓same product

RuoYi 4.8.0 — privilege escalation przez brak walidacji parametru deptId