CVE-2023-54400: Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any remote attacker who can reach the AjaxMethod.ashx endpoint can exploit it. No authentication or prior access is required.
What access and impact can exploitation provide?
An attacker can use UNION-based SQL injection through the Name parameter of the getEmpByname action against the Microsoft SQL Server backend. This can allow extraction, disclosure, and modification of database contents, with potential further compromise of the underlying server.
How can defenders identify likely exposure or attempted exploitation?
Systems running Fumasoft Fumeng Cloud should check whether AjaxMethod.ashx is externally reachable and review requests targeting the getEmpByname action with crafted values in the Name parameter. Exploitation evidence was first observed on 2023-10-18.