SQL Injection Vulnerability in Fumasoft Fumeng Cloud Product
CVE-2023-54400

9.3CRITICAL

Key Information:

Vendor

Fumasoft

Vendor
CVE Published:
29 September 2026

What is CVE-2023-54400?

Fumasoft Fumeng Cloud is affected by a SQL injection vulnerability found in the AjaxMethod.ashx endpoint. This security flaw allows unauthenticated remote attackers to exploit the system by injecting arbitrary SQL commands through the Name parameter in the getEmpByname action. The vulnerability poses a significant risk as it enables malicious actors to execute UNION-based SQL injection techniques against the Microsoft SQL Server backend. Consequently, this could lead to unauthorized access, data disclosure, and potential modifications within the database, ultimately compromising the integrity of the underlying server. The first evidence of this exploitation was recorded by the Shadowserver Foundation on October 18, 2023.

Affected Version(s)

Fumeng Cloud *

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Shadowserver Foundation
.