cve/2024/CVE-2024-54762.md

18 lines
736 B
Markdown
Raw Normal View History

2025-09-29 16:08:36 +00:00
### [CVE-2024-54762](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54762)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
2025-09-29 21:09:30 +02:00
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
2025-09-29 16:08:36 +00:00
### Description
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
### POC
#### Reference
2025-09-29 21:09:30 +02:00
- https://locrian-lightning-dc7.notion.site/CVE-2024-54762-1748e5e2b1a280b4a549dcce2c4823e8
2025-09-29 16:08:36 +00:00
#### Github
- https://github.com/Lunax0/CVE_List