Security Advisory

CVE-2024-42900

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-08-28 00:00:00
Last updated 2024-08-28 15:58:49
Assigner mitre
State PUBLISHED

Description

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.