CVE-2023-54403

CVE-2023-54403 published: Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePa...

View full NVD advisory → ← Back to CVE watch