๐Ÿ” CVE Alert

CVE-2024-58385

CRITICAL 9.8

Yonyou U8 CRM SQL Injection via fillbacksettingedit.php

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.

CWE CWE-89
Vendor yonyou
Product u8 crm
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for yonyou u8 crm

Be the first to know when new critical vulnerabilities affecting yonyou u8 crm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Yonyou / U8 CRM
18 16.5 16.1 16.0 15.1 13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.yonyou.com: https://security.yonyou.com/#/noticeInfo?id=618 cn-sec.com: https://cn-sec.com/archives/3234745.html yonyou.com: https://www.yonyou.com/Global/ vulncheck.com: https://www.vulncheck.com/advisories/yonyou-u8-crm-sql-injection-via-fillbacksettingedit-php

Credits

๐Ÿ” The Shadowserver Foundation