CVE-2024-54762

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-09 20:15

Updated : 2025-05-14 18:26


NVD link : CVE-2024-54762

Mitre link : CVE-2024-54762

CVE.ORG link : CVE-2024-54762


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')