Description
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
Remediation
References
https://gist.github.com/Maverickfir/53405b944b2830b43a84abf4b1734847
https://github.com/Maverickfir/RuoYi-v4.6-vulnerability/blob/main/Ruoyiv4.6.md
Related Vulnerabilities
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2022-36010 Vulnerability in npm package react-editable-json-tree
CVE-2014-10065 Vulnerability in npm package remarkable
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2022-1233 Vulnerability in maven package org.webjars.npm:urijs