Executive brief
Yonyou U8cloud is an enterprise cloud ERP platform used by mid-market and large organizations to manage finance, supply chain, sales, and collaboration. A SQL injection vulnerability in the /u8cloud/openapi/so.saleorder.sendaudit endpoint allows remote attackers to extract sensitive data from the database, potentially exposing customer, financial, and operational information without authentication.
Technical details
The OpenAPI endpoint /u8cloud/openapi/so.saleorder.sendaudit fails to properly sanitize the "operator" parameter, allowing SQL injection attacks via POST requests. An unauthenticated attacker can exploit this network-accessible endpoint to execute arbitrary SQL queries and retrieve sensitive database contents. The vulnerability has been publicly disclosed with functional exploit code available.
Affected products
- Yonyou U8cloud 5.x
Timeline
- 2026-07-14: disclosed: Exploit published publicly on GitHub
- 2026-09-22: advisory: NVD entry published