RULE(RULE ID:338594)

Rule General Information
Release Date: 2024-12-10
Rule Name: Yonyou GRP-U8 taskmanager_login SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou GRP-U8 Administrative and Public Financial Management Software is a new generation product launched by Yonyou Corporation, focusing on the national electronic government affairs sector. It is the most professional government financial management software in China's administrative and financial field, based on cloud computing technology. There is a SQL injection vulnerability exists in the taskmanager_login interface. An unauthenticated attacker could execute arbitrary SQL statements through the vulnerability, which may result in the disclosure of sensitive information and even gain system privileges on the server.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.