CVE-2025-66736
EUVD-2025-20474822.12.2025, 21:15
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| youlai | youlai-boot | 2.21.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration