SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
References
| Link | Resource |
|---|---|
| https://gitee.com/y_project/RuoYi/commit/ddd858ca732618a472b10eaab2f8e4b45812ffc5 | Patch Permissions Required |
| https://gitee.com/y_project/RuoYi/issues/IBC976 | Issue Tracking |
| https://github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC/blob/main/README.md | Exploit Third Party Advisory |
| https://github.com/mrlihd/Ruoyi-4.7.9-SQL-Injection-PoC | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-23 17:15
Updated : 2026-01-06 17:34
NVD link : CVE-2024-57521
Mitre link : CVE-2024-57521
CVE.ORG link : CVE-2024-57521
JSON object : View
Products Affected
ruoyi
- ruoyi
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
