<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fumasoft - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/fumasoft/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:28:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/fumasoft/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated SQL Injection in Fumasoft Fumeng Cloud</title><link>https://feed.craftedsignal.io/briefs/2026-09-fumasoft-sql-injection/</link><pubDate>Tue, 29 Sep 2026 16:28:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-fumasoft-sql-injection/</guid><description>Fumasoft Fumeng Cloud contains a critical SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to execute arbitrary database queries.</description><content:encoded><![CDATA[<p>Fumasoft Fumeng Cloud is affected by a critical SQL injection vulnerability identified as CVE-2023-54400. The vulnerability exists within the AjaxMethod.ashx endpoint, specifically within the getEmpByname action. Unauthenticated remote attackers can inject arbitrary SQL commands through the Name parameter, which is processed by the underlying Microsoft SQL Server backend. Successful exploitation allows attackers to extract, disclose, or modify sensitive database contents. In advanced scenarios, this SQL injection can be leveraged to achieve remote code execution on the underlying host server. The Shadowserver Foundation reported observing exploitation of this vulnerability in the wild as early as October 18, 2023. Given the severity and the availability of proof-of-concept vectors, organizations using Fumeng Cloud should prioritize remediation.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 score of 9.8, indicating a critical severity. Exploitation results in the loss of confidentiality, integrity, and availability of data stored within the Fumeng Cloud database. If the database service account is running with elevated privileges, the impact extends to full server compromise, allowing attackers to pivot into the internal network or deploy further malicious payloads.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching of Fumasoft Fumeng Cloud installations. As the vulnerability is actively exploited in the wild, identify and monitor logs for anomalous HTTP POST requests to the AjaxMethod.ashx endpoint.</p>
<ul>
<li>Audit web server logs for HTTP requests containing SQL syntax (e.g., UNION, SELECT, OR, 1=1) targeting the AjaxMethod.ashx endpoint.</li>
<li>Implement strict input validation on the Name parameter for all API endpoints in Fumeng Cloud.</li>
<li>Restrict access to the AjaxMethod.ashx endpoint to trusted IP addresses if immediate patching is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>web-application</category><category>sql-injection</category><category>active-exploitation</category></item></channel></rss>