Advisory · CVE-2023-54403
Yonyou U8 CRM auth bypass and file read leak credentials to unauthenticated attackers
A DontCheckLogin parameter skips authentication on getemaildata.php, and an unvalidated filePath parameter lets remote attackers read arbitrary files, including database and service credentials.
- Vendor
- Yonyou
- Product
- U8 CRM
- Identifier / CWE
- CVE-2023-54403
CWE-22, CWE-863 - Action timing
- Immediate
Explain it like I’m five
The CRM has a back door marked 'do not check my ID' and, once inside, lets visitors read any file on the computer, including the files that hold passwords.
- 01Unauthenticated request
A remote attacker calls /ajax/getemaildata.php with the DontCheckLogin=1 parameter, which bypasses the login check.
- 02Unvalidated path
The filePath parameter is passed to the file reader without validation or confinement to the web directory.
- 03Traversal
Path traversal sequences reach sensitive files outside the web application directory, including configuration files with database or service credentials.
- 04Credential theft
The attacker reads and exfiltrates the file contents, gaining credentials for deeper access into the enterprise environment.
What happened
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php. The endpoint honors a DontCheckLogin=1 parameter that skips authentication entirely, and its filePath parameter is not validated or confined to the web directory. Unauthenticated remote attackers can combine the two to read arbitrary files on the server, including configuration files that contain database or service credentials. NVD lists releases 13, 15.1, 16.0, and 16.1 as affected, and V16.5 and V18 as not affected.
The Shadowserver Foundation observed exploitation of this flaw in the wild as early as October 2023. The vulnerability is rated high at CVSS 8.7.
What to do
- Identify exposed Yonyou U8 CRM deployments, including internet-facing instances.
- Upgrade to V16.5 or V18, following the Yonyou security notice.
- Restrict network access to the CRM application while remediation is underway.
- Rotate database, service, and administrative credentials that were stored in files reachable from the web server.
- Review web server and application logs for requests to getemaildata.php carrying DontCheckLogin or unusual filePath values.
Management note
An authentication bypass plus an arbitrary file read in a widely deployed enterprise CRM, with exploitation observed in the wild for nearly three years, is a credential-theft pipeline aimed at the systems that hold customer and business data. The patch is necessary but not sufficient: assume credentials that lived on affected servers are compromised and rotate them as part of the same change.