CVE-2022-23869

Source
https://cve.org/CVERecord?id=CVE-2022-23869
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23869.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23869
Published
2022-03-30T10:15:55Z
Modified
2026-08-12T03:51:17Z
Summary
[none]
Details

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23869.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "v4.7.2"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/yangzongzhuan/ruoyi

Affected ranges

Type
GIT
Repo
https://github.com/yangzongzhuan/ruoyi
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:ruoyi:ruoyi:4.7.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.7.2"
        },
        {
            "last_affected": "4.7.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

4.*
4.7.2
v4.*
v4.7.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23869.json"