CVE-2024-54762 - CERT CVE
ID CVE-2024-54762
Sažetak Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
Reference
CVSS
Base: 6.3
Impact: 3.4
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 10-01-2025 - 16:15
Objavljeno 09-01-2025 - 20:15