CVE-2023-54403
Received Received - Intake

Unauthenticated File Read in Yonyou U8 CRM

Vulnerability report for CVE-2023-54403, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
yonyou u8_crm to 16.5 (exc)
yonyou u8_crm From 18 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary file read issue in Yonyou U8 CRM versions before V16.5 and V18. It exists in the /ajax/getemaildata.php endpoint where unauthenticated attackers can bypass authentication using the DontCheckLogin=1 parameter. They can then read arbitrary files by exploiting an unvalidated filePath parameter, including sensitive files outside the web application directory.

Detection Guidance

To detect this vulnerability, check if the affected Yonyou U8 CRM versions are running and if the /ajax/getemaildata.php endpoint is accessible. Test by sending a request with DontCheckLogin=1 and a filePath parameter pointing to a sensitive file like /etc/passwd or a configuration file. Example: curl 'http://target.com/ajax/getemaildata.php?DontCheckLogin=1&filePath=/etc/passwd'

Monitor network traffic for unusual requests to /ajax/getemaildata.php with the DontCheckLogin parameter. Check server logs for repeated attempts to access arbitrary file paths.

Impact Analysis

Attackers can exploit this flaw to read sensitive files, including configuration files containing database or service credentials. This could lead to unauthorized access to sensitive data, potential data breaches, and further compromise of the affected system or network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may result in non-compliance with regulations like GDPR or HIPAA. Exposure of personal or health data could lead to legal penalties, fines, and reputational damage due to failure to protect sensitive information.

Mitigation Strategies

Immediately upgrade Yonyou U8 CRM to version V16.5 or V18 or later to patch the vulnerability. If upgrading is not possible, restrict access to the /ajax/getemaildata.php endpoint via firewall rules or web server configuration.

Disable the DontCheckLogin parameter if it is not required for functionality. Review and remove any unnecessary file read permissions for the web application user.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54403. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart