CVE-2025-28408 | RuoYi 4.8.0 /selectDeptTree/ selectDeptTree deptId improper authorization (EUVD-2025-10357)
A vulnerability was found in RuoYi 4.8.0. It has been declared as critical. This vulnerability affects the function selectDeptTree of the file /selectDeptTree/. The manipulation of the argument deptId leads to improper authorization.
This vulnerability was named CVE-2025-28408. The attack can be initiated remotely. There is no exploit available.