CVE-2023-54400: Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname

Published Sep 29, 2026
·
Updated

Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.

Affected Software

1 affected component
Fumasoft Fumeng Cloud

Event History

Sep 29, 2026
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any remote attacker who can reach the AjaxMethod.ashx endpoint can exploit it. No authentication or prior access is required.

2

What access and impact can exploitation provide?

An attacker can use UNION-based SQL injection through the Name parameter of the getEmpByname action against the Microsoft SQL Server backend. This can allow extraction, disclosure, and modification of database contents, with potential further compromise of the underlying server.

3

How can defenders identify likely exposure or attempted exploitation?

Systems running Fumasoft Fumeng Cloud should check whether AjaxMethod.ashx is externally reachable and review requests targeting the getEmpByname action with crafted values in the Name parameter. Exploitation evidence was first observed on 2023-10-18.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203