PT-2025-52769 · Ruoyi · Ruoyi

Published

2025-12-23

·

Updated

2026-01-06

·

CVE-2024-57521

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RuoYi versions prior to 4.7.9
Description A SQL Injection issue exists in RuoYi versions prior to 4.7.9. This allows a remote attacker to execute arbitrary code through the createTable function located in SqlUtil.java. The vulnerability is present in the createTable function and can be exploited via a crafted request.
Recommendations Update RuoYi to version 4.7.9 or later.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-57521

Affected Products

Ruoyi