Product
An unauthenticated SQL injection vulnerability in Yonyou U8 CRM allows attackers to execute arbitrary SQL commands via the fillbacksettingedit.php endpoint, potentially leading to remote code execution on MS SQL Server instances.