NVD HIGH: CVE-2023-54403 — Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability...
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files cont
CVE-2023-54403