Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2023-54400 2026-09-29

Fumasoft Fumeng Cloud Unauthenticated SQL Injection (CVE-2023-54400)

"CVE-2023-54400 is a critical (CVSS 9.8) unauthenticated SQL injection flaw in Fumasoft Fumeng Cloud's `AjaxMethod.ashx` endpoint, and the Shadowserver Foundation first observed exploitation evidence on 2023-10-18."

CVE-2023-54400 is a critical (CVSS 9.8) unauthenticated SQL injection flaw in Fumasoft Fumeng Cloud's AjaxMethod.ashx endpoint, and the Shadowserver Foundation first observed exploitation evidence on 2023-10-18.

What Is It

CVE-2023-54400 is a SQL injection vulnerability (CWE-89) in Fumasoft Fumeng Cloud. The flaw is in the AjaxMethod.ashx endpoint. Attackers can inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication.

According to the NVD description, attackers can use UNION-based SQL injection against the Microsoft SQL Server backend. This lets them extract, disclose, and modify database contents, and could lead to further compromise of the underlying server.

VulnCheck assigned the CVE, and NVD published it on 2026-09-29. The NVD record is in "Received" status.

Why It Matters

What's Vulnerable

NVD lists no CPEs for this record yet.

Patch Status

The supplied KEV and NVD data contain no information about a patch, fixed version, or vendor remediation. Because every version is listed as affected, assume all Fumeng Cloud deployments are exposed until the vendor says otherwise. There is no CISA KEV required action or due date because the CVE has no KEV listing. Check the VulnCheck advisory for updates on remediation.

Sources