Sceawere

Vulnerability Detail

CVE-2023-54400UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Fumasoft Fumeng SQL Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
9h ago
Vendor
Fumasoft
Product
Fumeng Cloud
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-29T16:17:04.070Z",
  "pubdate": "2026-09-29T16:17:04.070Z",
  "executiveSummary": "Fumasoft Fumeng Cloud is susceptible to a critical SQL injection vulnerability located within the AjaxMethod.ashx handler. This flaw allows unauthenticated remote actors to execute arbitrary SQL commands against the Microsoft SQL Server backend by manipulating the Name parameter during the getEmpByname action. Because the application fails to adequately sanitize user-supplied input before passing it to database queries, it is susceptible to UNION-based injection attacks. Successful exploitation enables unauthorized actors to bypass authentication mechanisms, perform data exfiltration, modify database contents, and potentially escalate privileges to achieve further compromise of the underlying server infrastructure. The vulnerability is externally exploitable and poses a severe risk to data confidentiality, integrity, and availability. Evidence of active exploitation in the wild was documented by the Shadowserver Foundation as of October 18, 2023. Organizations utilizing affected versions of Fumasoft Fumeng Cloud must treat this as a high-priority security issue, as the lack of authentication requirements facilitates easy, automated exploitation by remote attackers.",
  "technicalDetails": "The vulnerability resides in the AjaxMethod.ashx component of the Fumasoft Fumeng Cloud platform. Specifically, the getEmpByname action fails to implement rigorous input validation or parameterization on the Name parameter, which acts as a vector for injecting malicious SQL syntax. This flaw constitutes a classic SQL injection vulnerability, specifically manifesting as a UNION-based injection against a Microsoft SQL Server backend.\nThe attack flow commences with a remote, unauthenticated HTTP request targeting the AjaxMethod.ashx endpoint. An attacker provides a crafted payload within the Name parameter of the getEmpByname action. When the backend receives this request, it concatenates the unsanitized input directly into a dynamic SQL query string executed by the database engine. By injecting UNION SELECT statements, an attacker can append the results of arbitrary queries to the original response, effectively bypassing intended data access controls.\nExploitation allows for the systematic enumeration of the database schema, including table and column names. Following schema mapping, attackers can exfiltrate sensitive data such as administrative credentials, user records, or business-critical information. Furthermore, depending on the service account permissions configured for the database, an attacker may leverage this access to modify, delete, or inject new records into the database. In environments where the database service account has excessive privileges, such as sysadmin roles, it may be possible to execute xp_cmdshell or other administrative stored procedures, facilitating full remote code execution on the underlying host operating system.\nThis vulnerability is particularly severe due to its accessibility over the network without the requirement for valid credentials. Since the application does not perform any authorization checks prior to processing the request in AjaxMethod.ashx, it is trivially exploitable by automated scripts and botnets. The exposure is exacerbated by the reliance on dynamic query construction, which lacks the structural separation between code and data typically enforced by parameterized queries or stored procedures. Post-exploitation impact ranges from complete loss of data confidentiality and integrity to potential server-side compromise, providing a foothold for further lateral movement within the network environment."
}
CVE-2023-54400: Fumasoft Fumeng SQL Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere