CRITICAL
9.8 CVE-2024-58385 Published 15 Sept 2026
Yonyou U8 CRM SQL Injection Vulnerability
Worried this affects one of your servers?
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability.
Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands.
Reference: CVE-2024-58385 on NVD
← Back to Security News