CyberRota Analysis
AI-GeneratedYonyou U8 CRM is vulnerable due to an unauthenticated SQL injection flaw in the fillbacksettingedit.php endpoint, allowing attackers to bypass authentication and execute arbitrary SQL commands. This critical vulnerability can lead to severe impacts, including the ability to write backdoor files and execute arbitrary operating system commands on Microsoft SQL Server deployments with xp_cmdshell enabled. Organizations using Yonyou U8 CRM should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.