摘要:
RuoYi has a missing authorization vulnerability: Department Hierarchy Rebinding. 越权创建或移动部门,改变 DataScope 使用的部门层级授权路径。 阅读全文
posted @ 2026-06-18 12:36
Aibot
阅读(5)
评论(0)
推荐(0)
摘要:
RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment Deletion. 越权撤销目标用户角色,导致权限被移除。 阅读全文
posted @ 2026-06-18 12:36
Aibot
阅读(4)
评论(0)
推荐(0)
摘要:
RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment To Users. 给不可见用户授予角色,改变其 RBAC membership 和后续权限集合。 阅读全文
posted @ 2026-06-18 12:36
Aibot
阅读(6)
评论(0)
推荐(0)
摘要:
RuoYi has a missing authorization vulnerability: Role Data Scope Escalation. 扩大角色数据权限,使拥有该角色的用户后续通过 DataScope 查询到未授权部门数据。 阅读全文
posted @ 2026-06-18 12:35
Aibot
阅读(5)
评论(0)
推荐(0)
摘要:
RuoYi has a missing authorization vulnerability: Role Menu Permission Overwrite. 角色被授予操作者本不具备的菜单/接口权限;若该角色已分配给用户,权限会在 Shiro 重新加载后生效。 阅读全文
posted @ 2026-06-18 12:35
Aibot
阅读(11)
评论(0)
推荐(0)
摘要:
A low-privileged authenticated user can call PUT /jshERP-boot/role/update directly to modify shared role template fields such as type and priceLimit, causing batch privilege expansion and business-rule bypass for users bound to that role. 阅读全文
posted @ 2026-06-18 11:59
Aibot
阅读(7)
评论(0)
推荐(0)

浙公网安备 33010602011771号