SQL Injection Vulnerability in Fumasoft Fumeng Cloud Product
CVE-2023-54400
9.3CRITICAL
What is CVE-2023-54400?
Fumasoft Fumeng Cloud is affected by a SQL injection vulnerability found in the AjaxMethod.ashx endpoint. This security flaw allows unauthenticated remote attackers to exploit the system by injecting arbitrary SQL commands through the Name parameter in the getEmpByname action. The vulnerability poses a significant risk as it enables malicious actors to execute UNION-based SQL injection techniques against the Microsoft SQL Server backend. Consequently, this could lead to unauthorized access, data disclosure, and potential modifications within the database, ultimately compromising the integrity of the underlying server. The first evidence of this exploitation was recorded by the Shadowserver Foundation on October 18, 2023.
Affected Version(s)
Fumeng Cloud *
