Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Thu, 09 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-09T00:00:00
Updated: 2025-01-10T15:52:41.854Z
Reserved: 2024-12-06T00:00:00
Link: CVE-2024-54762
Vulnrichment
Updated: 2025-01-10T15:52:23.522Z
NVD
Status : Awaiting Analysis
Published: 2025-01-09T20:15:39.140
Modified: 2025-01-10T16:15:29.337
Link: CVE-2024-54762
Redhat
No data.