Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kkll5875

#25880of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2024-30202
9.8
2024-08-26
Ruoyi Cms · Ruoyi Cms · CVE-2024-42913
**Name of the Vulnerable Software and Affected Versions** RuoYi CMS versions prior to 4.7.9 **Description** The issue is related to a SQL injection vulnerability. It can be exploited via the `job id` parameter at the "/sasfs1" endpoint. This allows an unauthenticated attacker to manipulate the `job id` and potentially compromise data. The vulnerability affects on-prem deployments. **Recommendations** For versions prior to 4.7.9, upgrade to a version greater than 4.7.9 to mitigate the risks. As a temporary workaround, consider restricting access to the "/sasfs1" endpoint or avoiding the use of the `job id` parameter until the issue is resolved.