CVE-2023-49371: SQL Injection
Published Dec 1, 2023
·Updated
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
Affected Software
2 affected components
maven/com.ruoyi:ruoyi<=4.6
Ruoyi Ruoyi<=4.6.0
Event History
Dec 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:31 PM
Frequently Asked Questions
1
What is the vulnerability ID of RuoYi?
The vulnerability ID of RuoYi is CVE-2023-49371.
2
What is the severity level of CVE-2023-49371?
The severity level of CVE-2023-49371 is not specified.
3
How does the SQL injection vulnerability occur in RuoYi?
The SQL injection vulnerability occurs in RuoYi via the /system/dept/edit endpoint.
4
Which version of RuoYi is affected by CVE-2023-49371?
CVE-2023-49371 affects RuoYi up to version 4.6.
5
Where can I find more information about CVE-2023-49371?
You can find more information about CVE-2023-49371 at the following references: [GitHub](https://github.com/Maverickfir/RuoYi-v4.6-vulnerability/blob/main/Ruoyiv4.6.md), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-49371), [GitHub Advisories](https://github.com/advisories/GHSA-fg29-37px-c7wm).