CVE-2025-4819

A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of the file /monitor/online/batchForceLogout of the component Offline Logout. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

19 May 2025, 13:35

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como problemática en y_project RuoYi 4.8.0. La vulnerabilidad afecta a una función desconocida del archivo /monitor/online/batchForceLogout del componente Offline Logout. La manipulación de los identificadores de los argumentos provoca una autorización incorrecta. Es posible ejecutar el ataque de forma remota. La complejidad del ataque es bastante alta. Se considera que su explotación es difícil. Se ha hecho público el exploit y puede que sea utilizado.

17 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-17 06:15

Updated : 2025-05-19 13:35


NVD link : CVE-2025-4819

Mitre link : CVE-2025-4819

CVE.ORG link : CVE-2025-4819


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization