Unauthenticated SQL Injection in Fumasoft Fumeng Cloud
Fumasoft Fumeng Cloud contains a critical SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to execute arbitrary database queries.
CVE search metadata
CVE search record: CVE-2023-54400. Severity: critical. CVSS: 9.8. KEV: no. Product: Fumeng Cloud. Brief: Unauthenticated SQL Injection in Fumasoft Fumeng Cloud. Brief link: https://feed.craftedsignal.io/briefs/2026-09-fumasoft-sql-injection/
Fumasoft Fumeng Cloud is affected by a critical SQL injection vulnerability identified as CVE-2023-54400. The vulnerability exists within the AjaxMethod.ashx endpoint, specifically within the getEmpByname action. Unauthenticated remote attackers can inject arbitrary SQL commands through the Name parameter, which is processed by the underlying Microsoft SQL Server backend. Successful exploitation allows attackers to extract, disclose, or modify sensitive database contents. In advanced scenarios, this SQL injection can be leveraged to achieve remote code execution on the underlying host server. The Shadowserver Foundation reported observing exploitation of this vulnerability in the wild as early as October 18, 2023. Given the severity and the availability of proof-of-concept vectors, organizations using Fumeng Cloud should prioritize remediation.
Impact
The vulnerability carries a CVSS v3.1 score of 9.8, indicating a critical severity. Exploitation results in the loss of confidentiality, integrity, and availability of data stored within the Fumeng Cloud database. If the database service account is running with elevated privileges, the impact extends to full server compromise, allowing attackers to pivot into the internal network or deploy further malicious payloads.
Recommendation
Prioritize patching of Fumasoft Fumeng Cloud installations. As the vulnerability is actively exploited in the wild, identify and monitor logs for anomalous HTTP POST requests to the AjaxMethod.ashx endpoint.
- Audit web server logs for HTTP requests containing SQL syntax (e.g., UNION, SELECT, OR, 1=1) targeting the AjaxMethod.ashx endpoint.
- Implement strict input validation on the Name parameter for all API endpoints in Fumeng Cloud.
- Restrict access to the AjaxMethod.ashx endpoint to trusted IP addresses if immediate patching is not possible.
Immediate actions
Deploy detection rule for AjaxMethod.ashx SQL injection
Mitigations
Identify and patch all instances of Fumeng Cloud
CVE-2023-54400
Detection coverage 1
Detect CVE-2023-54400 Exploitation - SQL Injection in AjaxMethod.ashx
criticalDetects attempts to exploit CVE-2023-54400 by identifying SQL injection keywords in the Name parameter sent to the AjaxMethod.ashx endpoint.
Detection queries are available on the platform. Get full rules →