Yonyou U8 Crm vulnerabilities
2 known vulnerabilities affecting yonyou/u8_crm.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-58385P1CRITICALCVSS 9.8Exploitedv18v16.5+4 more2026-09-15
CVE-2024-58385 [CRITICAL] CWE-89 CVE-2024-58385: Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL S
nvd
CVE-2023-54403P1HIGHCVSS 7.5Exploitedv16.1v16.0+2 more2026-09-30
CVE-2023-54403 [HIGH] CWE-22 CVE-2023-54403: Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemailda
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application
nvd