← back
CVE-2023-54400criticalobserved exploitationCWE-89

Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.3epss 0.5%
from disclosure to weapon
Published on NVDSep 29
VulnCheckSep 29
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
yesVulnCheck
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Fumasoft · Fumeng Cloud