Description
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

Yonyou U8 CRM contains an unauthenticated SQL injection flaw in the fillbacksettingedit.php configuration endpoint. The DontCheckLogin=1 parameter bypasses authentication, and the id parameter is inserted directly into SQL queries without sanitization. Attackers can inject arbitrary SQL statements, and on Microsoft SQL Server deployments with xp_cmdshell enabled they can write backdoor files and execute operating system commands by any client that can reach the endpoint, potentially allowing a remote attacker to gain full system compromise.

Affected Systems

Yonyou U8 CRM is affected; specific version information was not disclosed. Administrators should verify whether their deployment uses the fillbacksettingedit.php endpoint and check for the presence of the DontCheckLogin parameter.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity exploit with complete confidentiality, integrity, and availability impact. The EPSS score is < 1%, indicating a very low, but nonzero, exploitation probability, yet the vulnerability was observed in the wild in February 2025, signalling active exploitation. The flaw is unauthenticated and reachable over the network, making it trivial for attackers to attempt exploitation without prior access. The lack of KEV listing does not diminish the risk, as the exploit can lead to arbitrary code execution on backend servers.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to the latest release to fix the unauthenticated SQL injection in fillbacksettingedit.php.
  • Restrict network access to the fillbacksettingedit.php endpoint so that only trusted internal or authenticated administrative users can reach it, and enforce authentication for all requests.
  • Disable or restrict xp_cmdshell on Microsoft SQL Server instances to prevent arbitrary command execution via SQL injection.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Title Yonyou U8 CRM SQL Injection via fillbacksettingedit.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:21:38.574Z

Reserved: 2026-09-15T16:00:59.385Z

Link: CVE-2024-58385

cve-icon Vulnrichment

Updated: 2026-09-21T18:21:35.021Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:09.697

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-58385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')