CVE-2023-54403
Published 30 September 2026 · tracked since 1 October 2026
Description
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this fl
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97661 HIGH 7.2
- CVE-2026-92244 HIGH 7.2
- CVE-2026-95687 HIGH 8.8
- CVE-2026-96268 MEDIUM 6.4
- CVE-2026-96573 HIGH 7.2
- CVE-2026-96813 HIGH 7.2
- CVE-2026-15983 HIGH 8.1
- CVE-2026-85235 HIGH 7.2
- CVE-2026-89424 MEDIUM 6.4
- CVE-2026-90992 MEDIUM 6.4