CRITICAL 9.3 NVD
CVE-2024-58385
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
References
- https://cn-sec.com/archives/3234745.html
- https://security.yonyou.com/#/noticeInfo?id=618
- https://www.vulncheck.com/advisories/yonyou-u8-crm-sql-injection-via-fillbacksettingedit-p
- https://www.yonyou.com/Global/
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-15 via NVD.
Risk Timeline
CVE Disclosed2026-09-15 · -1 days ago
Remediation Resources
Official Advisory
security.yonyou.com/#/noticeInfo?id=618Analysis & PoC
cn-sec.com/archives/3234745.htmlAnalysis & PoC
www.yonyou.com/Global/
vulnfeed aggregates 14340 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.