← Back

Youlai Boot

youlai-boot

Vendor: Youlai • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youlai
1Youlai Boot
Jun 17, 2026
Dec 22, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to impor...Show more
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.Show less
1Youlai
1Youlai Boot
Jun 17, 2026
Dec 22, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.
1Youlai
1Youlai Boot
Jun 17, 2026
Nov 26, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.
1Youlai
1Youlai Boot
Jun 17, 2026
Nov 26, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.