SQL Injection Vulnerability in Ruoyi Framework by Yangzongzhuan
CVE-2024-54762
6.3MEDIUM
What is CVE-2024-54762?
The Ruoyi framework, specifically version 4.7.9 and earlier, is susceptible to an SQL injection vulnerability due to inadequate filtering of SQL keywords within the filterKeyword method. This flaw enables attackers to execute arbitrary SQL queries, potentially compromising the integrity and confidentiality of the database. Organizations using this software should promptly assess their systems and apply relevant mitigations.