High severity7.5NVD Advisory· Published Nov 26, 2025· Updated Jun 17, 2026
CVE-2025-46174
CVE-2025-46174
Description
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- gist.github.com/Han-tj/29543ce0dae8cbb3bcbedca3390844a9nvdThird Party Advisory
- gitee.com/y_project/RuoYi/issues/IC1JZRnvdIssue TrackingVendor Advisory
- gitee.com/y_project/RuoYi/commit/ea4af7a8cf54393b11d3d286e0aaeb3df8a9aaefnvdPermissions Required
News mentions
0No linked articles in our index yet.