PT-2024-30202 · Ruoyi Cms · Ruoyi Cms
Kkll5875
·
Published
2024-08-26
·
Updated
2025-03-26
·
CVE-2024-42913
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RuoYi CMS versions prior to 4.7.9
Description
The issue is related to a SQL injection vulnerability. It can be exploited via the
job id parameter at the "/sasfs1" endpoint. This allows an unauthenticated attacker to manipulate the job id and potentially compromise data. The vulnerability affects on-prem deployments.Recommendations
For versions prior to 4.7.9, upgrade to a version greater than 4.7.9 to mitigate the risks. As a temporary workaround, consider restricting access to the "/sasfs1" endpoint or avoiding the use of the
job id parameter until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruoyi Cms