Critical severity10.0OSV Advisory· Published Dec 23, 2025· Updated Jun 17, 2026
CVE-2024-57521
CVE-2024-57521
Description
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: v2.2, v2.3, v2.4, …
Patches
Vulnerability mechanics
References
3- gitee.com/y_project/RuoYi/commit/ddd858ca732618a472b10eaab2f8e4b45812ffc5nvdPatchPermissions Required
- github.com/mrlihd/CVE-2024-57521-SQL-Injection-PoC/blob/main/README.mdnvdExploitThird Party Advisory
- gitee.com/y_project/RuoYi/issues/IBC976nvdIssue Tracking
News mentions
0No linked articles in our index yet.