PatchSiren cyber security CVE debrief
CVE-2024-58385 Yonyou CVE debrief
CVE-2024-58385 is a critical unauthenticated SQL injection vulnerability in Yonyou U8 CRM's fillbacksettingedit.php configuration endpoint. The vulnerability allows attackers to execute arbitrary SQL commands and potentially write backdoor files and execute operating system commands on Microsoft SQL Server deployments with xp_cmdshell enabled. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
- Vendor
- Yonyou
- Product
- U8 CRM
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Defenders and security teams responsible for Yonyou U8 CRM deployments should assess exposure and prioritize remediation. This vulnerability requires immediate attention due to its critical severity and potential for exploitation.
Why it matters
CVE-2024-58385 is a critical SQL injection vulnerability in Yonyou U8 CRM that allows attackers to execute arbitrary SQL commands and potentially write backdoor files and execute operating system commands. Defenders and security teams responsible for Yonyou U8 CRM deployments should assess exposure and prioritize remediation due to the critical severity and potential for exploitation.
- Potential for arbitrary SQL command execution
- Possible write backdoor files and execute operating system commands on Microsoft SQL Server deployments
- Requires verification of affected versions and remediation status
- Prioritize inventory checks and monitoring for suspicious activity
Technical summary
The vulnerability exists in the fillbacksettingedit.php configuration endpoint of Yonyou U8 CRM, where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. This allows attackers to execute arbitrary SQL commands and potentially write backdoor files and execute operating system commands on Microsoft SQL Server deployments with xp_cmdshell enabled.
Defensive priority
High
Recommended defensive actions
- Review and update Yonyou U8 CRM configurations to prevent exploitation
- Implement additional security measures to detect and prevent SQL injection attacks
- Monitor for suspicious activity and update incident response plans accordingly
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the vendor and affected versions are not clearly identified. The Shadowserver Foundation observed exploitation evidence on 2025-02-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-58385 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-58385
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-58385 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58385
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cn-sec.com/archives/3234745.html
-
Source reference
Unverified legacy reference
URL: https://security.yonyou.com/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/yonyou-u8-crm-sql-injection-via-fillbacksettingedit-php
-
Source reference
Unverified legacy reference
URL: https://www.yonyou.com/Global/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.