← Back

CVE-2024-54762

nvd nist
Published: Jan 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.

Affected (1)

Products: Ruoyi: Ruoyi
1 product
Ruoyi
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.7.9

Timeline

No history available yet.