Description
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
Remediation
References
https://gist.github.com/Maverickfir/53405b944b2830b43a84abf4b1734847
https://github.com/Maverickfir/RuoYi-v4.6-vulnerability/blob/main/Ruoyiv4.6.md
Related Vulnerabilities
CVE-2019-10294 Vulnerability in maven package org.jenkins-ci.plugins:kmap-jenkins
CVE-2021-4133 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2021-22964 Vulnerability in npm package fastify-static
CVE-2016-10633 Vulnerability in npm package dwebp-bin
CVE-2014-3623 Vulnerability in maven package org.apache.cxf:cxf