20210607/cve_public

20210607/cve_public

Releases0
Stars5

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

8.8 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges

7.2 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

8.8 HIGH

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

6.7 MEDIUM

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method