CVE-2024-57439

An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*

History

14 May 2025, 18:26

Type Values Removed Values Added
References () https://gitee.com/y_project/RuoYi - () https://gitee.com/y_project/RuoYi - Product
References () https://github.com/peccc/restful_vul/blob/main/ruoyi_dos/ruoyi_dos.md - () https://github.com/peccc/restful_vul/blob/main/ruoyi_dos/ruoyi_dos.md - Exploit, Third Party Advisory
References () https://github.com/yangzongzhuan/RuoYi - () https://github.com/yangzongzhuan/RuoYi - Product
References () https://ruoyi.vip/ - () https://ruoyi.vip/ - Product
CPE cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*
Summary
  • (es) Un problema en la interfaz de restablecimiento de contraseña de ruoyi v4.8.0 permite a atacantes con privilegios de administrador provocar una denegación de servicio (DoS) al duplicar el nombre de inicio de sesión de la cuenta.
First Time Ruoyi
Ruoyi ruoyi

29 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-281
References () https://github.com/peccc/restful_vul/blob/main/ruoyi_dos/ruoyi_dos.md - () https://github.com/peccc/restful_vul/blob/main/ruoyi_dos/ruoyi_dos.md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9

29 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 15:15

Updated : 2025-05-14 18:26


NVD link : CVE-2024-57439

Mitre link : CVE-2024-57439

CVE.ORG link : CVE-2024-57439


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE
CWE-281

Improper Preservation of Permissions