CVE-2024-57436

RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-29 15:15

Updated : 2025-05-14 18:26


NVD link : CVE-2024-57436

Mitre link : CVE-2024-57436

CVE.ORG link : CVE-2024-57436


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE
CWE-922

Insecure Storage of Sensitive Information