CVE-2024-58385
Yonyou U8 CRM SQL Injection via fillbacksettingedit.php
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
| CWE | CWE-89 |
| Vendor | yonyou |
| Product | u8 crm |
| Published | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for yonyou u8 crm
Be the first to know when new critical vulnerabilities affecting yonyou u8 crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Yonyou / U8 CRM
18 16.5 16.1 16.0 15.1 13
References
Credits
๐ The Shadowserver Foundation