Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-23869

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-23869
  • Ruoyi » Ruoyi » Version: 4.7.2
    cpe:2.3:a:ruoyi:ruoyi:4.7.2


Contact Us

Shodan ® - All rights reserved