References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3relobjreportlist.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://zhuanlan.zhihu.com/p/1888250324424316046 https://mrxn.net/jswz/yonyon-u8crm-borrowout-ajaxgetborrowdata-sqli.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8+CRM%E7%B3%BB%E7%BB%9Fleadconversion.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.gdust.edu.cn/jszx/wlaq1/xxtb/index.aspx?id=171 https://juejin.cn/post/7472735368924790794 https://www.cnblogs.com/fengzun/articles/18365219 https://www.yingjikeji.cn/sys-nd/685.html https://mrxn.net/jswz/yonyon-u8crm-pub-objectview-ID-sqli.html https://www.ufida168.com/case_detail/3694.html https://cn-sec.com/archives/3522173.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9FgetDeptName%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3256931.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3setremindtoold.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E6%8E%A5%E5%8F%A3rellistname.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnvd.org.cn/flaw/show/CNVD-2025-00101
Related Vulnerabilities用友U8CRM存在SQL注入漏洞PoCyonyou-u8-crm-getemaildata-fileread: 用友 U8 CRM客户关系管理系统 getemaildata.php 任意文件读取漏洞用友-U8CRM checkselectworksheet.php SQL注入漏洞用友U8CRM /datacache/crmdebug.log 信息泄露漏洞用友U8CRM eventsetlist 存在SQL注入漏洞用友U8CRM biztype 存在 SQL 注入漏洞用友U8CRM setting.php 任意文件上传漏洞用友-U8CRM attrlist.php SQL注入漏洞用友U8CRM rellistname.php SQL注入漏洞用友U8CRM ajaxgetborrowdata.php SQL注入漏洞用友U8CRM eventsetlist.php SQL注入漏洞用友网络 U8CRM 任意文件读取漏洞