CVE-2025-3199
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2025-3199 is a critical vulnerability affecting the ageerle ruoyi-ai software up to version 2.0.1. This issue lies in an unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java within the API Interface. The flaw results in improper authorization, enabling attackers to manipulate the system remotely. The exploit has become publicly available, increasing the risk of attacks. To mitigate this vulnerability, users are advised to upgrade to version 2.0.2, which bears the patch c0daf641fb25b244591b7a6c3affa35c69d321fe.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.