CVE-2022-48114: SQL Injection
Published Feb 2, 2023
·Updated
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
Affected Software
1 affected component
Ruoyi Ruoyi<=4.7.5
Event History
Feb 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this RuoYi vulnerability?
The vulnerability ID for this RuoYi vulnerability is CVE-2022-48114.
2
What is the severity of CVE-2022-48114?
The severity of CVE-2022-48114 is critical with a CVSS score of 9.8.
3
What component is affected by CVE-2022-48114?
The component affected by CVE-2022-48114 is /tool/gen/createTable.
4
What is the affected software version of CVE-2022-48114?
The affected software version of CVE-2022-48114 is RuoYi up to v4.7.5.
5
How can I fix the SQL injection vulnerability in RuoYi?
To fix the SQL injection vulnerability in RuoYi, update to a version higher than v4.7.5.