Impact
Yonyou U8 CRM contains an unauthenticated SQL injection flaw in the fillbacksettingedit.php configuration endpoint. The DontCheckLogin=1 parameter bypasses authentication, and the id parameter is inserted directly into SQL queries without sanitization. Attackers can inject arbitrary SQL statements, and on Microsoft SQL Server deployments with xp_cmdshell enabled they can write backdoor files and execute operating system commands by any client that can reach the endpoint, potentially allowing a remote attacker to gain full system compromise.
Affected Systems
Yonyou U8 CRM is affected; specific version information was not disclosed. Administrators should verify whether their deployment uses the fillbacksettingedit.php endpoint and check for the presence of the DontCheckLogin parameter.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity exploit with complete confidentiality, integrity, and availability impact. The EPSS score is < 1%, indicating a very low, but nonzero, exploitation probability, yet the vulnerability was observed in the wild in February 2025, signalling active exploitation. The flaw is unauthenticated and reachable over the network, making it trivial for attackers to attempt exploitation without prior access. The lack of KEV listing does not diminish the risk, as the exploit can lead to arbitrary code execution on backend servers.
OpenCVE Enrichment