CVE-2023-54400 is a critical (CVSS 9.8) unauthenticated SQL injection flaw in Fumasoft Fumeng Cloud's AjaxMethod.ashx endpoint, and the Shadowserver Foundation first observed exploitation evidence on 2023-10-18.
What Is It
CVE-2023-54400 is a SQL injection vulnerability (CWE-89) in Fumasoft Fumeng Cloud. The flaw is in the AjaxMethod.ashx endpoint. Attackers can inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication.
According to the NVD description, attackers can use UNION-based SQL injection against the Microsoft SQL Server backend. This lets them extract, disclose, and modify database contents, and could lead to further compromise of the underlying server.
VulnCheck assigned the CVE, and NVD published it on 2026-09-29. The NVD record is in "Received" status.
Why It Matters
- Critical severity: The CVSS 3.1 base score is 9.8 (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and the CVSS 4.0 score is 9.3. Both are rated CRITICAL. - Easy to exploit remotely: An attacker can exploit it over the network with low complexity, no privileges, and no user interaction.
- Exploitation seen in the wild: The NVD record says the Shadowserver Foundation first observed exploitation evidence on 2023-10-18. That is almost three years before the CVE was published.
- Public exploit templates: The references include a Goby proof of concept and a ProjectDiscovery Nuclei template, so automated scanning for this flaw is realistic.
- Not in KEV: No CISA KEV entry was provided for this CVE, so KEV does not currently confirm active exploitation. The exploitation evidence comes from the NVD description.
What's Vulnerable
- Vendor: Fumasoft
- Product: Fumeng Cloud
- Versions: All versions (
*) are listed as affected - Component: the
getEmpBynameaction in theAjaxMethod.ashxendpoint (Nameparameter) - Backend: Microsoft SQL Server
NVD lists no CPEs for this record yet.
Patch Status
The supplied KEV and NVD data contain no information about a patch, fixed version, or vendor remediation. Because every version is listed as affected, assume all Fumeng Cloud deployments are exposed until the vendor says otherwise. There is no CISA KEV required action or due date because the CVE has no KEV listing. Check the VulnCheck advisory for updates on remediation.