In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.
References
Link Resource
https://gitee.com/y_project/RuoYi/issues/I4RCO2 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-30T10:15:55

Updated: 2022-03-30T10:15:55

Reserved: 2022-01-24T00:00:00


Link: CVE-2022-23869

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-30T11:15:07.697

Modified: 2022-04-04T19:48:04.813


Link: CVE-2022-23869

JSON object: View

cve-icon Redhat Information

No data.

CWE