CVE-2025-66735
EUVD-2025-20474222.12.2025, 21:15
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| youlai | youlai-boot | 2.21.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration