RULE(RULE ID:338578)

Rule General Information
Release Date: 2024-12-04
Rule Name: Yonyou U8-CRM System ajaxgetborrowdata.php getWarehouseOtherInfo SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou is a leading provider of enterprise management software and cloud services in China, and Yonyou U8-CRM is an integrated customer relationship management solution. There is SQL injection vulnerability in getWarehouseOtherInfo method of Yonyou U8-CRM system ajaxgetborrowdata.php, through which an unauthenticated attacker executes arbitrary SQL statements, calls xp_cmdshell to write backdoor files, executes arbitrary code, The server permission is obtained.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.