RULE(RULE ID:339087)

Rule General Information
Release Date: 2025-06-18
Rule Name: Yonyou U8 reservationcomplete.php Remote Code Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou U8 is an ERP management software designed for small and medium-sized enterprises, covering core functions such as finance, supply chain, and production manufacturing. It helps businesses achieve refined management and information technology upgrades. There is a remote code execution vulnerability in the reservationcomplete.php file of Yonyou U8. The vulnerability arises from insufficient validation of user input parameters. Attackers can exploit this vulnerability to execute arbitrary code on the server.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.