CRITICAL
9.8 CVE-2023-54400 Published 29 Sept 2026
Fumasoft Fumeng Cloud SQL Injection Vulnerability
Worried this affects your website?
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint.
Unauthenticated remote attackers can inject arbitrary SQL through the Name parameter of the getEmpByname action. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend.
- Impact: extract, disclose, and modify database contents.
- Potential for further compromise of the underlying server.
- Exploitation evidence first observed by the Shadowserver Foundation on 2023-10-18.
Reference: CVE-2023-54400 on NVD
← Back to Security News