RULE(RULE ID:339200)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou GRP-U8 sqcxIndex.jsp SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yoniu GRP-U8 Administrative and Institutional Financial Management Software is a next-generation product developed by Yoniu Corporation, focusing on national e-government initiatives and based on cloud computing technology. It is the most professional government financial management software in China's administrative and institutional financial sector. The key parameter in the /u8qx/sqcxIndex.jsp interface is vulnerable to SQL injection. Attackers can craft malicious requests to execute arbitrary SQL statements on the server, leading to sensitive information disclosure and, in severe cases, remote code execution.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.