CVE-2024-57437: SQL Injection
Published Jan 29, 2025
·Updated
RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
Affected Software
2 affected components
Ruoyi Ruoyi
Ruoyi Ruoyi=4.8.0
Event History
Jan 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-57437?
CVE-2024-57437 has been classified as a medium severity vulnerability due to its potential for exploitation through SQL injection.
2
How do I fix CVE-2024-57437?
To fix CVE-2024-57437, validate and sanitize user inputs for the orderby parameter to prevent SQL injection.
3
What kind of vulnerability is CVE-2024-57437?
CVE-2024-57437 is a SQL injection vulnerability located in the orderby parameter of the /monitor/online/list endpoint.
4
Which software versions are affected by CVE-2024-57437?
CVE-2024-57437 affects RuoYi version 4.8.0.
5
Can CVE-2024-57437 be exploited remotely?
Yes, CVE-2024-57437 can potentially be exploited remotely by attackers who send specially crafted requests.