SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
References
| Link | Resource |
|---|---|
| https://gitee.com/y_project/RuoYi/commit/ddd858ca732618a472b10eaab2f8e4b45812ffc5 | Patch Permissions Required |
| https://gitee.com/y_project/RuoYi/issues/IBC976 | Issue Tracking |
| https://github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC/blob/main/README.md | Exploit Third Party Advisory |
| https://github.com/mrlihd/Ruoyi-4.7.9-SQL-Injection-PoC | Exploit Third Party Advisory |
Configurations
History
06 Jan 2026, 17:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ruoyi:ruoyi:*:*:*:*:*:*:*:* | |
| First Time |
Ruoyi
Ruoyi ruoyi |
|
| References | () https://gitee.com/y_project/RuoYi/commit/ddd858ca732618a472b10eaab2f8e4b45812ffc5 - Patch, Permissions Required | |
| References | () https://gitee.com/y_project/RuoYi/issues/IBC976 - Issue Tracking | |
| References | () https://github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC/blob/main/README.md - Exploit, Third Party Advisory | |
| References | () https://github.com/mrlihd/Ruoyi-4.7.9-SQL-Injection-PoC - Exploit, Third Party Advisory |
23 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
23 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 17:15
Updated : 2026-01-06 17:34
NVD link : CVE-2024-57521
Mitre link : CVE-2024-57521
CVE.ORG link : CVE-2024-57521
JSON object : View
Products Affected
ruoyi
- ruoyi
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
