CRITICAL 9.8 CVE-2023-54400 Published 29 Sept 2026

Fumasoft Fumeng Cloud SQL Injection Vulnerability

Worried this affects your website?

Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint.

Unauthenticated remote attackers can inject arbitrary SQL through the Name parameter of the getEmpByname action. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend.

  • Impact: extract, disclose, and modify database contents.
  • Potential for further compromise of the underlying server.
  • Exploitation evidence first observed by the Shadowserver Foundation on 2023-10-18.

Reference: CVE-2023-54400 on NVD

← Back to Security News