Yonyou U8 CRM Arbitrary File Read via getemaildata.php
63Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 8.7epss 0.7%
from disclosure to weapon
Published on NVDSep 30
VulnCheckSep 30
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Yonyou · U8 CRM⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/oa/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20getemaildata.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.mdhttps://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-lfi.yamlhttps://security.yonyou.com/#/noticeInfo?id=624https://www.vulncheck.com/advisories/yonyou-u8-crm-arbitrary-file-read-via-getemaildata-phphttps://www.yonyou.com/Global/