RULE(RULE ID:338586)

Rule General Information
Release Date: 2024-12-04
Rule Name: Yonyou NC process Interface SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyon NC is a high-end enterprise ERP software launched by Yonyon Company. It is designed for large enterprises and group enterprises, providing comprehensive core business management functions such as financial management, supply chain management, and human resource management, supporting enterprises' complex business scenarios and high concurrent data processing requirements. The SQL injection vulnerability exists in the process interface of the Yonyon NC system. An unauthenticated attacker executes any SQL statement through the vulnerability, calls xp_cmdshell to write the backdoor file, executes any code, and obtains the server permission.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.