Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ruoyi
Ruoyi ruoyi |
|
CPEs | cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ruoyi
Ruoyi ruoyi |
Fri, 10 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Thu, 09 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-09T00:00:00
Updated: 2025-01-10T15:52:41.854Z
Reserved: 2024-12-06T00:00:00
Link: CVE-2024-54762

Updated: 2025-01-10T15:52:23.522Z

Status : Analyzed
Published: 2025-01-09T20:15:39.140
Modified: 2025-05-14T18:26:00.927
Link: CVE-2024-54762

No data.