On September 11, 2020, Tencent Security detected an SQL injection vulnerability in Yonyou GRP-U8 internal control and management software for government affairs. Attackers can use a carefully constructed payload to perform SQL injection attacks in order to get sensitive database information.
Exploitations in the wild (ITW) have been detected, and Tencent Cloud WAF supports defense against them.
Attackers can use a carefully constructed payload to perform SQL injection attacks in order to get sensitive database information, and Tencent Cloud WAF currently supports defense against them.
Yonyou GRP-U8 internal control and management software for government affairs.
According to the vulnerability advisory, there is currently no official update. Tencent Security recommends you:
Was this page helpful?