PT-2025-3068 · Ruoyi · Ruoyi

Published

2025-01-09

·

Updated

2025-05-14

·

CVE-2024-54762

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ruoyi versions 4.7.9 and earlier
Description The issue is related to an authenticated SQL injection risk. This occurs because the filterKeyword method does not fully filter SQL injection keywords, leading to a potential SQL injection risk.
Recommendations For Ruoyi versions 4.7.9 and earlier, as a temporary workaround, consider disabling the filterKeyword method until a patch is available. Restrict access to sensitive database operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-54762

Affected Products

Ruoyi