PT-2026-79431 · Dromara · Ruoyi-Vue-Plus
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dromara RuoYi-Vue-Plus versions prior to 5.6.3
Description
Improper authorization exists within the Workflow Endpoint component. This issue allows a remote attacker to perform unauthorized actions through the following functions:
FlwInstanceController(), FlwDefinitionController(), FlwCategoryController(), FlwSpelController(), and TestLeaveController().Recommendations
Update Dromara RuoYi-Vue-Plus to version 5.6.3 or later.
As a temporary mitigation, restrict access to the
FlwInstanceController(), FlwDefinitionController(), FlwCategoryController(), FlwSpelController(), and TestLeaveController() functions.Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi-Vue-Plus