Vendor
critical
threat
Unauthenticated SQL Injection in Yonyou U8 CRM (CVE-2024-58385)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability in Yonyou U8 CRM allows attackers to execute arbitrary SQL commands via the fillbacksettingedit.php endpoint, potentially leading to remote code execution on MS SQL Server instances.
exploited
U8 CRM
web-application
sql-injection
remote-code-execution
cve-2024-58385
1r
2t
1c
critical
threat
Unauthenticated RCE in Yonyou U8 Cloud via Java Deserialization
1 rule 2 TTPs 1 CVEYonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability (CVE-2023-54398) in the FileManageServlet component, enabling remote attackers to achieve arbitrary OS command execution.
exploited
U8 Cloud
1r
2t
1c