CVE-2024-57436

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/01/2025
Last modified:
14/05/2025

Description

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*