SQL Injection Vulnerability in RuoYi Web Application by Yangzongzhuan
CVE-2024-57437
6.5MEDIUM
What is CVE-2024-57437?
A critical SQL injection vulnerability was identified in RuoYi v4.8.0, allowing unauthorized SQL queries to be executed through the 'orderby' parameter in the online monitoring page. This flaw can potentially expose sensitive data and compromise the application's integrity. Users are advised to implement security measures to prevent exploitation. For detailed mitigation strategies, please refer to the available documentation and security advisories.