Yonyou CRM is a software developed by Yonyou, which is specially designed to help enterprises manage customer related business activities. The Yonyou CRM system has a logic vulnerability at the reservationcomplete.php interface, through which an attacker can directly go into the background to obtain background permissions, so as to prepare for subsequent access to server permissions. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021. Other reference:None