CVE-2023-54403
published 2026-09-30CVE-2023-54403: Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass…
PriorityP181high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.46%
37.8th percentile
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| yonyou | u8_crm | — | — |
| yonyou | u8_crm | — | — |
| yonyou | u8_crm | — | — |
| yonyou | u8_crm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 par
ghsa_unreviewed·2026-09-30
CVE-2023-54403 [HIGH] CWE-22 Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 par
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
VulDB
Yonyou U8 CRM up to 17 /ajax/getemaildata.php filePath path traversal
vuldb·2026-09-30·CVSS 7.5
CVE-2023-54403 [HIGH] Yonyou U8 CRM up to 17 /ajax/getemaildata.php filePath path traversal
A vulnerability was found in Yonyou U8 CRM up to 17 and classified as problematic. This impacts an unknown function of the file /ajax/getemaildata.php. Such manipulation of the argument filePath leads to path traversal.
This vulnerability is listed as CVE-2023-54403. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
VulnCheck
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2023·CVSS 7.5
CVE-2023-54403 [HIGH] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://ww
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/oa/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20getemaildata.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.mdhttps://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-lfi.yamlhttps://security.yonyou.com/#/noticeInfo?id=624https://www.vulncheck.com/advisories/yonyou-u8-crm-arbitrary-file-read-via-getemaildata-phphttps://www.yonyou.com/Global/
2026-09-30
Published
Exploited in the wild