CVE-2024-54762

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*

History

14 May 2025, 18:26

Type Values Removed Values Added
CPE cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:*
References () https://github.com/yangzongzhuan/RuoYi/ - () https://github.com/yangzongzhuan/RuoYi/ - Product
References () https://locrian-lightning-dc7.notion.site/CVE-2024-54762-1748e5e2b1a280b4a549dcce2c4823e8 - () https://locrian-lightning-dc7.notion.site/CVE-2024-54762-1748e5e2b1a280b4a549dcce2c4823e8 - Exploit
First Time Ruoyi
Ruoyi ruoyi

09 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 20:15

Updated : 2025-05-14 18:26


NVD link : CVE-2024-54762

Mitre link : CVE-2024-54762


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE

No CWE.