CVE-2023-54400
Received Received - Intake

SQL Injection in Fumeng Cloud via AjaxMethod.ashx

Vulnerability report for CVE-2023-54400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
fumasoft fumeng_cloud *
fumasoft fumeng_cloud to 2023-10-18 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in Fumasoft Fumeng Cloud's AjaxMethod.ashx endpoint. It allows unauthenticated remote attackers to inject malicious SQL commands through the Name parameter of the getEmpByname action. Attackers can exploit UNION-based SQL injection to extract, disclose, or modify database contents, potentially compromising the underlying server.

Detection Guidance
  • Use Nuclei with the provided template to scan for the vulnerability by sending a request to /Ajax/AjaxMethod.ashx with action=getEmpByname and a test payload. Check if the response contains an MD5 hash of a known value.
  • Inspect network traffic for suspicious SQL injection attempts targeting the Name parameter in the getEmpByname action of AjaxMethod.ashx.
  • Monitor logs for repeated failed login attempts or unusual database queries involving UNION-based SQL injection techniques.
Impact Analysis

This vulnerability can lead to unauthorized access to sensitive data, data manipulation or deletion, and potential full server compromise. Attackers could steal confidential information, alter records, or gain control over the database server without authentication.

Compliance Impact

This vulnerability can severely impact compliance with GDPR and HIPAA by enabling unauthorized access to personal and sensitive data. It may result in data breaches, leading to legal penalties, reputational damage, and loss of trust due to failure to protect confidential information.

Mitigation Strategies
  • Apply patches or updates provided by Fumasoft to fix the SQL injection flaw in the AjaxMethod.ashx endpoint.
  • Implement input validation and parameterized queries to prevent SQL injection attacks on the Name parameter.
  • Restrict access to the /Ajax/AjaxMethod.ashx endpoint to trusted IP addresses or networks.
  • Monitor database activity for unauthorized access or modifications and investigate suspicious queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart