CVE-2023-54400 Fumasoft Fumeng Cloud SQL注入漏洞
影响未授权攻击者可读取、篡改数据库数据,并可能进一步入侵服务器
Fumasoft Fumeng Cloud 的 AjaxMethod.ashx 接口存在 SQL 注入漏洞。攻击者无需认证即可通过 getEmpByname 操作的 Name 参数注入任意 SQL 语句。该漏洞已被 Shadowserver Foundation 观测到实际利用活动。
影响范围
受影响版本范围暂无公开信息,涉及 Fumasoft Fumeng Cloud 的 AjaxMethod.ashx 接口。
漏洞详情
漏洞类型为未授权 SQL 注入,成因是 getEmpByname 操作的 Name 参数未做有效过滤即拼接进 SQL 查询。攻击者可利用 UNION 注入技术针对后端 Microsoft SQL Server 提取、泄露和修改数据库内容。由于无需认证,利用门槛极低。
利用条件与风险
利用无需任何认证,可远程直接发起,CVSS 9.8 属严重级别,且已有在野利用证据,实战风险极高。
修复建议
建议联系厂商获取修复版本或补丁,对 Name 参数进行参数化查询与严格过滤;临时可限制 AjaxMethod.ashx 接口的访问来源并加强数据库权限管控。
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.