Skip to content
Threat Feed
critical threat exploited

Unauthenticated SQL Injection in Fumasoft Fumeng Cloud

Fumasoft Fumeng Cloud contains a critical SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to execute arbitrary database queries.

CVE search metadata

CVE search record: CVE-2023-54400. Severity: critical. CVSS: 9.8. KEV: no. Product: Fumeng Cloud. Brief: Unauthenticated SQL Injection in Fumasoft Fumeng Cloud. Brief link: https://feed.craftedsignal.io/briefs/2026-09-fumasoft-sql-injection/

Fumasoft Fumeng Cloud is affected by a critical SQL injection vulnerability identified as CVE-2023-54400. The vulnerability exists within the AjaxMethod.ashx endpoint, specifically within the getEmpByname action. Unauthenticated remote attackers can inject arbitrary SQL commands through the Name parameter, which is processed by the underlying Microsoft SQL Server backend. Successful exploitation allows attackers to extract, disclose, or modify sensitive database contents. In advanced scenarios, this SQL injection can be leveraged to achieve remote code execution on the underlying host server. The Shadowserver Foundation reported observing exploitation of this vulnerability in the wild as early as October 18, 2023. Given the severity and the availability of proof-of-concept vectors, organizations using Fumeng Cloud should prioritize remediation.

Impact

The vulnerability carries a CVSS v3.1 score of 9.8, indicating a critical severity. Exploitation results in the loss of confidentiality, integrity, and availability of data stored within the Fumeng Cloud database. If the database service account is running with elevated privileges, the impact extends to full server compromise, allowing attackers to pivot into the internal network or deploy further malicious payloads.

Recommendation

Prioritize patching of Fumasoft Fumeng Cloud installations. As the vulnerability is actively exploited in the wild, identify and monitor logs for anomalous HTTP POST requests to the AjaxMethod.ashx endpoint.

  • Audit web server logs for HTTP requests containing SQL syntax (e.g., UNION, SELECT, OR, 1=1) targeting the AjaxMethod.ashx endpoint.
  • Implement strict input validation on the Name parameter for all API endpoints in Fumeng Cloud.
  • Restrict access to the AjaxMethod.ashx endpoint to trusted IP addresses if immediate patching is not possible.

Immediate actions

Deploy detection rule for AjaxMethod.ashx SQL injection

Detection Engineering 24h

Mitigations

Identify and patch all instances of Fumeng Cloud

immediate IT Operations

CVE-2023-54400

Detection coverage 1

Detect CVE-2023-54400 Exploitation - SQL Injection in AjaxMethod.ashx

critical

Detects attempts to exploit CVE-2023-54400 by identifying SQL injection keywords in the Name parameter sent to the AjaxMethod.ashx endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →