CVE-2024-57521

CRITICAL

Ruoyi < 4.7.9 - SQL Injection

Title source: rule

Description

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

Exploits (2)

gitee 47,892 stars
by y_project · javawriteup
https://gitee.com/y_project/RuoYi/issues/IBC976
nomisec WORKING POC
by mrlihd · poc
https://github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC

Scores

CVSS v3 10.0
EPSS 0.0053
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
ruoyi/ruoyi < 4.7.9
Published Dec 23, 2025
Tracked Since Feb 18, 2026