Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-58385— Yonyou U8 CRM SQL Injection via fillbacksettingedit.php

Quick assessment

Affected
Yonyou U8 CRM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

用友 U8 CRM 存在一个未认证的 SQL 注入漏洞。在 fillbacksettingedit.php 配置端点中, 参数可绕过身份验证,且 参数未经过滤直接拼接到 SQL 查询语句中。攻击者可利用该缺陷执行任意 SQL 命令;在启用了 的 Microsoft SQL Server 部署环境中,攻击者还能写入后门文件并执行任意操作系统命令。该漏洞的利用证据首次由影子服务器基金会(Shadowserver Foundation)于 2025 年 2 月 13 日观察到。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 6

VendorProduct Version RangeStatus
Yonyou U8 CRM 18 affected
16.5 affected
16.1 affected
16.0 affected
15.1 affected
13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-58385

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Yonyou U8 CRM SQL Injection via fillbacksettingedit.php
Source: CVE Program / CVE List V5
Vulnerability Description
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Yonyou U8 CRM 18 -

II. Public POCs for CVE-2024-58385

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-58385

登录查看更多情报信息。

Vendor Advisories for CVE-2024-58385 (2)

Proof of Concept for CVE-2024-58385 (1)

Vendor Pages for CVE-2024-58385 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-58385

No comments yet


Leave a comment