CRITICAL
Yonyou
CVE published 2026-09-15
CVE-2024-58385
CVE-2024-58385 is a critical unauthenticated SQL injection vulnerability in Yonyou U8 CRM's fillbacksettingedit.php configuration endpoint. The vulnerability allows attackers to execute arbitrary SQL commands and potentially write backdoor files and execute operating system commands on Microsoft SQL Server deployments with xp_cmdshell enabled. Exploitation evidence was first observed by the Shadowserver F [truncated]