CVE-2025-10989

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.325912 Permissions Required VDB Entry
https://vuldb.com/?id.325912 Third Party Advisory VDB Entry
https://vuldb.com/?submit.653737 Third Party Advisory VDB Entry
https://www.cnblogs.com/aibot/p/19063507 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*

History

03 Oct 2025, 20:23

Type Values Removed Values Added
First Time Ruoyi
Ruoyi ruoyi
CPE cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.325912 - () https://vuldb.com/?ctiid.325912 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.325912 - () https://vuldb.com/?id.325912 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.653737 - () https://vuldb.com/?submit.653737 - Third Party Advisory, VDB Entry
References () https://www.cnblogs.com/aibot/p/19063507 - () https://www.cnblogs.com/aibot/p/19063507 - Exploit, Third Party Advisory

26 Sep 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-26 01:15

Updated : 2025-10-03 20:23


NVD link : CVE-2025-10989

Mitre link : CVE-2025-10989

CVE.ORG link : CVE-2025-10989


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization