CVE-2024-57521
CRITICALRuoyi < 4.7.9 - SQL Injection
Title source: ruleDescription
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
Exploits (2)
References (4)
Scores
CVSS v3
10.0
EPSS
0.0053
EPSS Percentile
67.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
ruoyi/ruoyi
< 4.7.9
Published
Dec 23, 2025
Tracked Since
Feb 18, 2026