CVE-2025-28408
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 7, 2025
Updated: Apr 9, 2025
CWE ID 284
Summary
CVE-2025-28408 is a newly disclosed vulnerability in RUoYi version 4.8.0. This issue permits a remote attacker to escalate privileges through the selectDeptTree method available at the /selectDeptTree/{deptId} endpoint. The deptId parameter lacks proper validation, allowing an adversary to manipulate it and exploit the vulnerability for elevated access. This can lead to significant security risks if not addressed promptly. Users are strongly urged to upgrade their RUoYi instances to a patched version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.