CVE-2024-57436

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
Configurations

No configuration.

History

29 Jan 2025, 17:15

Type Values Removed Values Added
References () https://github.com/peccc/restful_vul/blob/main/ruoyi_elevation_of_privileges/ruoyi_elevation_of_privileges.md - () https://github.com/peccc/restful_vul/blob/main/ruoyi_elevation_of_privileges/ruoyi_elevation_of_privileges.md -
CWE CWE-922
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

29 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 15:15

Updated : 2025-01-29 17:15


NVD link : CVE-2024-57436

Mitre link : CVE-2024-57436

CVE.ORG link : CVE-2024-57436


JSON object : View

Products Affected

No product.

CWE
CWE-922

Insecure Storage of Sensitive Information