VYPR
Medium severity6.5NVD Advisory· Published Mar 30, 2022· Updated Jun 17, 2026

CVE-2022-23869

CVE-2022-23869

Description

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Ruoyi/Ruoyi2 versions
    cpe:2.3:a:ruoyi:ruoyi:4.7.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ruoyi:ruoyi:4.7.2:*:*:*:*:*:*:*
    • (no CPE)range: 4.7.2
  • RuoYi/RuoYi v4.7.2description

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.