VYPR

U8 CRM

by Yonyou

CVEs (1)

  • CVE-2024-58385CriSep 15, 2026
    risk 0.64cvss 9.8epss

    Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can…