CVE-2024-57436

HIGH

RuoYi <4.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.

Scores

CVSS v3 7.2
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-922
Status published
Products (2)
com.ruoyi/ruoyi 0Maven
ruoyi/ruoyi 4.8.0
Published Jan 29, 2025
Tracked Since Feb 18, 2026