Ruoyi v.4.7.9 and before contains an authenticated SQL...
Moderate severity
Unreviewed
Published
Jan 9, 2025
to the GitHub Advisory Database
•
Updated Jan 10, 2025
Description
Published by the National Vulnerability Database
Jan 9, 2025
Published to the GitHub Advisory Database
Jan 9, 2025
Last updated
Jan 10, 2025
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
References