---
id: CVE-2024-58385
title: >-
  Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the
  fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1
  parameter bypasses authentication and the id parameter is incorporated into
  SQL querie…
summary: >-
  Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the
  fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1
  parameter bypasses authentication and the id parameter is incorporated into
  SQL querie…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Yonyou
product: U8 CRM
affected:
  - u8_crm 18
  - u8_crm 16.5
  - u8_crm 16.1
  - u8_crm 16.0
  - u8_crm 15.1
  - u8_crm 13
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:03.243'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58385'
references:
  - url: 'https://cn-sec.com/archives/3234745.html'
    label: disclosure@vulncheck.com
  - url: 'https://security.yonyou.com/#/noticeInfo?id=618'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yonyou-u8-crm-sql-injection-via-fillbacksettingedit-php
    label: disclosure@vulncheck.com
  - url: 'https://www.yonyou.com/Global/'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.0038
epssPercentile: 0.3189
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-21T18:21:21.803341Z'
ingestedAt: '2026-09-15T17:41:02.859Z'
---

## Overview

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
