CVE-2024-46076
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-46076 is a security vulnerability affecting RuoYi version 4.7.9 and earlier. This issue enables attackers to inject malicious code by escaping from comments within the code generation feature. The flaw allows attackers to bypass security restrictions, potentially resulting in unauthorized system access or data breaches. RuoYi users are strongly advised to update to a patched version to mitigate this risk. Attackers can exploit this vulnerability through specially crafted input, allowing them to execute arbitrary code with the privileges of the affected application. The impact of this vulnerability can range from information disclosure to full system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.