CVE-2025-4819

Source
https://cve.org/CVERecord?id=CVE-2025-4819
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4819.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-4819
Published
2025-05-17T06:00:06.145Z
Modified
2026-07-15T01:48:52.348626724Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
y_project RuoYi Offline Logout batchForceLogout improper authorization
Details

A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of the file /monitor/online/batchForceLogout of the component Offline Logout. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4819.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.8.0"
                },
                {
                    "last_affected": "4.8.0"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/yangzongzhuan/ruoyi

Affected ranges

Type
GIT
Repo
https://github.com/yangzongzhuan/ruoyi
Events
Database specific
{
    "cpe": "cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "4.8.0"
        },
        {
            "last_affected": "4.8.0"
        }
    ]
}

Affected versions

4.*
4.8.0
v4.*
v4.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4819.json"