CVE-2023-54403: Yonyou U8 CRM Arbitrary File Read via getemaildata.php
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Yonyou U8 CRMto a version that resolves this vulnerability.Fixed in V16.5 - Upgrade
Upgrade
Yonyou U8 CRMto a version that resolves this vulnerability.Fixed in V18
Event History
Frequently Asked Questions
Which deployments are exposed?
Yonyou U8 CRM deployments before V16.5, as well as V18, are affected when the /ajax/getemaildata.php endpoint is reachable. The issue can expose files outside the web application directory.
Does exploitation require an account or user interaction?
No. An unauthenticated attacker can use the DontCheckLogin=1 parameter to bypass authentication, and no user interaction is required.
What information could an attacker obtain?
An attacker can read arbitrary files through the unvalidated filePath parameter. This may include configuration files containing database or service credentials.
Is there evidence of exploitation in the wild?
Yes. The Shadowserver Foundation first observed exploitation evidence on 2023-10-14.