用友 U8 CRM 存在一个未认证的 SQL 注入漏洞。在 fillbacksettingedit.php 配置端点中, 参数可绕过身份验证,且 参数未经过滤直接拼接到 SQL 查询语句中。攻击者可利用该缺陷执行任意 SQL 命令;在启用了 的 Microsoft SQL Server 部署环境中,攻击者还能写入后门文件并执行任意操作系统命令。该漏洞的利用证据首次由影子服务器基金会(Shadowserver Foundation)于 2025 年 2 月 13 日观察到。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet