Aller au contenu

Fiche vulnérabilité

CVE-2025-10988 : faille élevée iocoder ruoyi-vue-pro (CVSS 8.8)

Description

A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • iocoder ruoyi-vue-pro

Références

Rechercher une autre vulnérabilité dans la base CVE