CVE-2024-58385: Yonyou U8 CRM SQL Injection via fillbacksettingedit.php

Published Sep 15, 2026
·
Updated

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xpcmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.

Affected Software

1 affected component
Yonyou U8 CRM

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove or block use of the DontCheckLogin=1 parameter for the fillbacksettingedit.php endpoint so unauthenticated requests cannot bypass login.

    Yonyou U8 CRM (fillbacksettingedit.php) DontCheckLogin = 1 (do not allow/disable the authentication bypass)
  2. Compensating control

    If xp_cmdshell is enabled in Microsoft SQL Server deployments, disable xp_cmdshell to prevent exploitation from writing backdoor files and executing arbitrary operating system commands.

Event History

Sep 15, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

Any remote attacker can exploit it without authentication or user interaction. The affected endpoint accepts DontCheckLogin=1 to bypass authentication, and the id parameter is used in SQL queries without sanitization.

2

What is the practical impact on Microsoft SQL Server deployments?

An attacker can execute arbitrary SQL commands. If xp_cmdshell is enabled, they may also write backdoor files and execute arbitrary operating system commands on the server.

3

How can I tell whether exploitation has occurred?

Review access and application logs for requests to fillbacksettingedit.php, particularly requests containing DontCheckLogin=1 and suspicious id parameter values. Also investigate unexpected SQL activity, newly written files, or operating system command execution where xp_cmdshell is enabled.

4

Is there evidence of active exploitation?

Yes. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203