A vulnerability was detected in Yonyou KSOA 9
Description
A vulnerability was detected in Yonyou KSOA 9
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
21 vulnerabilities from Yonyou
← Back to all CVEsA vulnerability was detected in Yonyou KSOA 9
A vulnerability was detected in Yonyou KSOA 9
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Yonyou KSOA 9
A security vulnerability has been detected in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LINXI666 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341772","name":"VDB-341772 | Yonyou KSOA HTTP GET Parameter select.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341772","name":"VDB-341772 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734593","name":"Submit #734593 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/18","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.758Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the folderid parameter of the select.jsp file, allowing remote unauthenticated attackers to execute arbitrary SQL commands.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 exposes enterprise data to unauthorized remote access and potential exfiltration.
Vulnerability Details
CVE-ID: CVE-2026-1178
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The application is susceptible to SQL injection via the folderid parameter in the /kmf/select.jsp endpoint. This flaw allows an unauthenticated remote attacker to manipulate database queries directly.
Business Impact
Successful exploitation of this vulnerability allows unauthorized actors to interface directly with the backend database, potentially leading to the compromise of sensitive enterprise data. Given the CVSS score of 7.3, this represents a significant risk to data confidentiality and integrity, which could result in regulatory non-compliance and reputational damage.
Remediation Plan
Immediate Action: Since no official vendor patch is currently available, restrict network access to the affected /kmf/select.jsp endpoint immediately.
Proactive Monitoring: Review web server access logs for anomalous requests containing SQL syntax or unusual characters in the folderid parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule designed to detect and block SQL injection patterns targeting the /kmf/select.jsp URI.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub issue.
Analyst Notes: As of January 21, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently exploitable because it does not require authentication and targets a common HTTP GET parameter.
Analyst Recommendation
The absence of a vendor-provided patch necessitates immediate defensive action to isolate the vulnerable component. Administrators must prioritize restricting access to the affected KSOA instance from untrusted networks and implement WAF filtering to mitigate the risk of exploitation while awaiting a formal security update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in Yonyou KSOA 9
A weakness has been identified in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LINXI666 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341771","name":"VDB-341771 | Yonyou KSOA HTTP GET Parameter save_folder.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341771","name":"VDB-341771 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734577","name":"Submit #734577 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/17","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.758Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 is vulnerable to SQL injection via the folderid parameter in /kmf/save_folder.jsp, allowing remote, unauthenticated attackers to execute malicious database queries.
Executive Summary:
A remote SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated attackers to potentially compromise system database integrity.
Vulnerability Details
CVE-ID: CVE-2026-1177
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the HTTP GET parameter handler of the /kmf/save_folder.jsp file. An unauthenticated attacker can trigger the vulnerability remotely by manipulating the folderid argument.
Business Impact
Successful exploitation of this SQL injection vulnerability could allow an attacker to read, modify, or delete sensitive data stored within the backend database. Given the CVSS score of 7.3, this represents a significant risk to confidentiality and integrity, potentially leading to unauthorized access to organizational information or service disruption.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict network access to the vulnerable /kmf/save_folder.jsp endpoint or disable the affected component if it is not business-critical.
Proactive Monitoring: Monitor web server logs for suspicious HTTP GET requests containing SQL syntax or unusual characters within the folderid parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection patterns targeting the identified endpoint.
Exploitation Status
Public Exploit Available: Yes โ a public proof-of-concept exists as documented in the referenced GitHub issue.
Analyst Notes: As of January 21, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability's remote, unauthenticated nature makes it highly accessible to attackers.
Analyst Recommendation
The presence of a public proof-of-concept and the lack of a vendor-supplied patch necessitate immediate defensive action. Organizations utilizing Yonyou KSOA 9.0 must prioritize isolating the affected component from external networks to prevent unauthorized data exposure while awaiting further guidance or security updates from the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LINXI666 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341723","name":"VDB-341723 | Yonyou KSOA HTTP GET Parameter folder.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341723","name":"VDB-341723 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734576","name":"Submit #734576 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/16","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.742Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 is vulnerable to a remote SQL injection flaw in the folderid parameter of the /kmf/folder.jsp component, allowing unauthenticated attackers to execute unauthorized database queries.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 permits unauthenticated remote attackers to manipulate database queries, posing a significant risk of unauthorized data access.
Vulnerability Details
CVE-ID: CVE-2026-1133
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The application fails to properly sanitize the folderid parameter within the /kmf/folder.jsp file, which is processed by the HTTP GET Parameter Handler. This vulnerability allows an unauthenticated attacker to perform remote SQL injection attacks.
Business Impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive information stored within the underlying database. Given the CVSS score of 7.3, this represents a high-severity risk that could result in significant data breaches, loss of confidentiality, and potential disruption of business operations reliant on the KSOA platform.
Remediation Plan
Immediate Action: As the vendor has not provided a patch, restrict access to the /kmf/folder.jsp endpoint via network-level controls or a Web Application Firewall (WAF) to block malicious SQL injection payloads.
Proactive Monitoring: Review web server access logs for suspicious requests targeting /kmf/folder.jsp, specifically looking for characters commonly used in SQL injection attacks such as single quotes, semicolons, and SQL keywords.
Compensating Controls: Implement strict input validation rules on the WAF to intercept and drop traffic containing SQL syntax in the folderid parameter.
Exploitation Status
Public Exploit Available: Yes โ a published proof-of-concept exists as documented in the referenced GitHub issue.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible as it requires no authentication and can be triggered remotely.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-supplied patch, this vulnerability presents an immediate risk to the organization. Administrators must prioritize the implementation of compensating controls, such as WAF filtering, to protect the affected endpoint until an official security update is released by Yonyou.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341722","name":"VDB-341722 | Yonyou KSOA HTTP GET Parameter edit_folder.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341722","name":"VDB-341722 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734568","name":"Submit #734568 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/15","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.742Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the folderid parameter of the /kmf/edit_folder.jsp file, allowing remote, unauthenticated attackers to execute arbitrary SQL commands.
Executive Summary:
An unauthenticated remote SQL injection vulnerability in Yonyou KSOA 9.0 poses a significant risk to enterprise data integrity and system confidentiality.
Vulnerability Details
CVE-ID: CVE-2026-1132
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the HTTP GET parameter handler for the folderid argument. It allows an unauthenticated remote attacker to perform unauthorized database operations through the /kmf/edit_folder.jsp endpoint.
Business Impact
The ability for an unauthenticated attacker to inject arbitrary SQL queries into the application database presents a severe risk of data breach, unauthorized data modification, or complete database compromise. With a CVSS score of 7.3, this flaw is categorized as high severity because it enables remote exploitation without requiring any user interaction or prior authentication.
Remediation Plan
Immediate Action: Since no official patch is currently available from the vendor, restrict external access to the /kmf/edit_folder.jsp endpoint immediately.
Proactive Monitoring: Review web access logs for unusual patterns or characters in URL parameters, particularly those targeting the folderid argument, which may indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule designed to detect and block common SQL injection patterns targeting the specified vulnerable endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the GitHub issue linked by the CVE record.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous due to its lack of authentication requirements and the accessibility of the vulnerable parameter.
Analyst Recommendation
Given the public availability of exploit material and the lack of a vendor-provided patch, organizations using Yonyou KSOA 9.0 must prioritize network-level mitigations. Apply strict access controls to the affected application components and monitor logs for indicators of compromise until a formal security update is released and verified.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in Yonyou KSOA 9
A vulnerability has been found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341721","name":"VDB-341721 | Yonyou KSOA HTTP GET Parameter save_catalog.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341721","name":"VDB-341721 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734566","name":"Submit #734566 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/13","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the /kmc/save_catalog.jsp file, allowing remote attackers to manipulate the catalogid parameter.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 permits unauthenticated remote attackers to execute arbitrary database queries, posing a severe risk to data integrity.
Vulnerability Details
CVE-ID: CVE-2026-1131
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This flaw is a SQL injection vulnerability (CWE-89) located in the /kmc/save_catalog.jsp endpoint. The vulnerability is triggered via the catalogid parameter and is exploitable by unauthenticated remote attackers.
Business Impact
The ability to perform SQL injection allows an attacker to bypass authentication, extract sensitive information from the backend database, or modify existing data. Given the CVSS score of 7.3, this represents a high risk to business operations, as it could lead to unauthorized access to proprietary records or total compromise of the application database.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict network access to the affected /kmc/save_catalog.jsp endpoint to trusted internal networks only.
Proactive Monitoring: Security teams should review web server access logs for anomalous HTTP GET requests containing SQL syntax or unusual characters within the catalogid parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule designed to detect and block SQL injection patterns targeting the specified JSP endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the reported GitHub issue (https://github.com/LX-66-LX/cve/issues/13).
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it allows unauthenticated remote interaction with the database layer.
Analyst Recommendation
Due to the lack of a vendor-supplied patch and the availability of a public proof-of-concept, this vulnerability poses an elevated risk. Organizations running Yonyou KSOA 9.0 must implement strict network segmentation and WAF filtering immediately to prevent potential exploitation while awaiting a formal security update from the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in Yonyou KSOA 9
A flaw has been found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341720","name":"VDB-341720 | Yonyou KSOA HTTP GET Parameter worksadd_plan.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341720","name":"VDB-341720 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734565","name":"Submit #734565 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/12","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows remote, unauthenticated attackers to manipulate database queries via the ID parameter in the worksheet/worksadd_plan.jsp component.
Executive Summary:
An unauthenticated SQL injection vulnerability in Yonyou KSOA 9.0 poses a significant risk of unauthorized database manipulation and information disclosure.
Vulnerability Details
CVE-ID: CVE-2026-1130
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) located in the HTTP GET parameter handler for the worksheet/worksadd_plan.jsp file. The flaw allows an unauthenticated remote attacker to inject malicious SQL commands through the ID argument.
Business Impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive data stored within the backend database, potentially resulting in data exfiltration or integrity loss. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to significant operational disruption if critical business data is compromised or modified.
Remediation Plan
Immediate Action: As no vendor-provided patch is currently available, administrators should restrict network access to the vulnerable worksheet/worksadd_plan.jsp file and the KSOA application to trusted IP addresses only.
Proactive Monitoring: Review web server access logs for anomalous GET requests containing SQL syntax or unusual characters directed at the worksheet/worksadd_plan.jsp endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection patterns specifically targeting URI parameters.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists via the GitHub repository referenced in the CVE record.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of required authentication.
Analyst Recommendation
The presence of a public proof-of-concept and the lack of a vendor-provided security update necessitate immediate defensive action. Organizations utilizing Yonyou KSOA 9.0 must prioritize isolating the affected application from public network exposure until a permanent fix is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Yonyou KSOA 9
A vulnerability was detected in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341719","name":"VDB-341719 | Yonyou KSOA HTTP GET Parameter worksadd.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341719","name":"VDB-341719 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734557","name":"Submit #734557 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/11","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the worksheet/worksadd.jsp file, allowing remote, unauthenticated attackers to manipulate the ID parameter.
Executive Summary:
An unauthenticated remote SQL injection vulnerability in Yonyou KSOA 9.0 poses a significant risk to data integrity and system security.
Vulnerability Details
CVE-ID: CVE-2026-1129
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The vulnerability is a SQL injection flaw (CWE-89) located in the /worksheet/worksadd.jsp file. An unauthenticated attacker can trigger this by sending a malicious HTTP GET request targeting the ID parameter.
Business Impact
The vulnerability allows unauthorized manipulation of database queries, which can lead to data exposure, unauthorized modification of records, or potential system compromise. With a CVSS score of 7.3, this flaw is categorized as High severity, reflecting the ease of remote exploitation and the potential for significant impact on enterprise data confidentiality and integrity.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict network access to the affected web application and monitor traffic for suspicious GET requests targeting the worksheet module.
Proactive Monitoring: Review web server access logs for anomalous patterns in URL parameters, specifically looking for SQL syntax characters such as single quotes or comment markers within the ID parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns in incoming HTTP requests.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists via the technical write-up on GitHub.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it allows unauthenticated interaction with the underlying database.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-supplied patch, this vulnerability presents an elevated risk to all deployments of Yonyou KSOA 9.0. Security teams must prioritize isolating the affected component from external networks until a formal fix is released by the vendor. Continuous monitoring of application logs is essential to detect any attempts to leverage this injection vector.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in Yonyou KSOA 9
A security flaw has been discovered in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341716","name":"VDB-341716 | Yonyou KSOA HTTP GET Parameter work_report.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341716","name":"VDB-341716 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734551","name":"Submit #734551 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/10","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the work_report.jsp file, allowing remote, unauthenticated attackers to manipulate the ID parameter and execute unauthorized database queries.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows remote, unauthenticated attackers to compromise database integrity and potentially exfiltrate sensitive information.
Vulnerability Details
CVE-ID: CVE-2026-1124
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) located within the HTTP GET parameter handler of the work_report.jsp file. The vulnerability is exploitable by remote, unauthenticated attackers who can manipulate the ID argument to execute arbitrary SQL commands.
Business Impact
Successful exploitation of this flaw allows attackers to gain unauthorized access to backend database contents, which may lead to the exfiltration of sensitive organizational data or unauthorized modification of records. Given the CVSS score of 7.3, this represents a high risk to data confidentiality and integrity, potentially resulting in severe reputational damage or regulatory non-compliance.
Remediation Plan
Immediate Action: As no official patch is currently available from the vendor, restrict network access to the affected work_report.jsp endpoint and implement strict input validation for the ID parameter to block malicious SQL syntax.
Proactive Monitoring: Review web server access logs for anomalous requests containing SQL keywords (such as SELECT, UNION, or OR 1=1) targeting the work_report.jsp endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets configured to detect and block SQL injection patterns specifically targeting the vulnerable JSP file.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the researcher write-up at https://github.com/LX-66-LX/cve/issues/10.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
This SQL injection vulnerability poses a significant risk due to its ease of exploitation and the lack of a vendor-provided patch. Organizations using Yonyou KSOA 9.0 must prioritize the implementation of perimeter-based compensating controls, such as WAF filtering, to mitigate the risk of unauthorized database access until the vendor releases a security update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was identified in Yonyou KSOA 9
A vulnerability was identified in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341715","name":"VDB-341715 | Yonyou KSOA HTTP GET Parameter work_mod.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341715","name":"VDB-341715 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734550","name":"Submit #734550 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/9","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the work_mod.jsp file, allowing remote attackers to manipulate the ID parameter via HTTP GET requests.
Executive Summary:
A remote SQL injection vulnerability in Yonyou KSOA 9.0 poses a significant risk of unauthorized database interaction and potential data compromise.
Vulnerability Details
CVE-ID: CVE-2026-1123
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the /worksheet/work_mod.jsp file. The vulnerability is exploitable by unauthenticated remote attackers through the ID HTTP GET parameter.
Business Impact
The ability to perform remote SQL injection allows an attacker to interact directly with the backend database, which may lead to the exfiltration of sensitive organizational data or the modification of application records. Given the CVSS score of 7.3, this high-severity flaw requires immediate attention to prevent unauthorized access and potential disruption to business operations.
Remediation Plan
Immediate Action: Since a vendor-supplied patch is currently unavailable, restrict external access to the affected /worksheet/work_mod.jsp endpoint. If possible, disable the specific functionality associated with this file until an official update is released.
Proactive Monitoring: Monitor web server logs for anomalous HTTP GET requests targeting /worksheet/work_mod.jsp, specifically looking for SQL syntax patterns within the ID parameter.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block common SQL injection payloads targeting the identified parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical documentation provided in the GitHub repository referenced by the CVE record.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is inherently dangerous due to its ease of exploitation and the lack of authentication required to trigger the injection.
Analyst Recommendation
Given the high-severity nature of this SQL injection vulnerability and the availability of a public proof-of-concept, organizations running Yonyou KSOA 9.0 should prioritize implementing network-level blocks to protect the vulnerable endpoint. Continuous monitoring for exploitation attempts is essential until the vendor provides an official patch to remediate the underlying code flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341714","name":"VDB-341714 | Yonyou KSOA HTTP GET Parameter work_info.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341714","name":"VDB-341714 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734549","name":"Submit #734549 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/8","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the HTTP GET parameter handler of the /worksheet/work_info.jsp file, allowing remote unauthenticated attackers to execute malicious queries.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to manipulate database queries, posing a significant risk to data integrity and confidentiality.
Vulnerability Details
CVE-ID: CVE-2026-1122
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The flaw exists within the HTTP GET parameter handler of the /worksheet/work_info.jsp file, where an improper neutralization of special elements used in an SQL command occurs. This vulnerability allows an unauthenticated, remote attacker to perform SQL injection by manipulating the ID argument.
Business Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information stored within the backend database. Given the CVSS score of 7.3, this represents a high-severity risk that could result in data exfiltration or potential compromise of the application integrity, causing significant operational disruption or reputational harm.
Remediation Plan
Immediate Action: Since no official patch is currently available from the vendor, restrict network access to the affected /worksheet/work_info.jsp endpoint to trusted IP addresses only.
Proactive Monitoring: Review web server and application logs for suspicious HTTP GET requests containing SQL syntax or unusual characters in the ID parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block incoming requests targeting the /worksheet/work_info.jsp file that contain suspicious SQL injection patterns.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the GitHub issue referenced by the CVE record.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The lack of vendor response increases the urgency for implementing independent network-level mitigations.
Analyst Recommendation
Organizations utilizing Yonyou KSOA 9.0 must treat this vulnerability with high priority due to the availability of public exploit information and the ease of remote, unauthenticated exploitation. Until the vendor provides a formal security update, administrators should implement strict ingress filtering and WAF protections to prevent unauthorized database access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341713","name":"VDB-341713 | Yonyou KSOA HTTP GET Parameter del_workplan.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341713","name":"VDB-341713 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734548","name":"Submit #734548 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/7","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.738Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the worksheet/del_workplan.jsp file, allowing unauthenticated remote attackers to manipulate the ID argument.
Executive Summary:
Yonyou KSOA 9.0 is susceptible to an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate back-end database queries.
Vulnerability Details
CVE-ID: CVE-2026-1121
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the HTTP GET parameter handler of the worksheet/del_workplan.jsp component. The vulnerability is exploitable by unauthenticated remote attackers via the ID argument.
Business Impact
Successful exploitation of this SQL injection vulnerability could allow an attacker to gain unauthorized access to sensitive data stored within the back-end database. With a CVSS score of 7.3, this flaw poses a high risk to data confidentiality and integrity, potentially leading to unauthorized information disclosure or database compromise.
Remediation Plan
Immediate Action: As no official patch is currently available from the vendor, restrict access to the /worksheet/del_workplan.jsp endpoint at the network or web server level to block all external traffic.
Proactive Monitoring: Monitor web server logs for suspicious HTTP GET requests containing SQL syntax or unusual characters in the ID parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection patterns targeting this specific endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the GitHub issue referenced by the vulnerability disclosure.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it allows unauthenticated interaction with database-backed components.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of vendor responsiveness, organizations utilizing Yonyou KSOA 9.0 must treat this as a high-priority risk. Immediate implementation of perimeter controls or WAF filtering is necessary to prevent unauthorized database access until a formal vendor-supplied security update is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in Yonyou KSOA 9
A vulnerability has been found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LX-66-LX (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341712","name":"VDB-341712 | Yonyou KSOA HTTP GET Parameter del_work.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341712","name":"VDB-341712 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734535","name":"Submit #734535 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/6","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.734Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the /worksheet/del_work.jsp component via the ID parameter, allowing remote attackers to execute arbitrary database queries.
Executive Summary:
A remote SQL injection vulnerability in Yonyou KSOA 9.0 exposes the backend database to unauthorized manipulation and potential data exfiltration.
Vulnerability Details
CVE-ID: CVE-2026-1120
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection flaw (CWE-89) triggered via the ID parameter within the /worksheet/del_work.jsp file. The vulnerability is remotely exploitable by unauthenticated attackers.
Business Impact
Successful exploitation allows an attacker to execute arbitrary SQL commands against the backend database, potentially leading to the unauthorized disclosure or modification of sensitive enterprise data. Given the CVSS score of 7.3, this represents a significant risk to data integrity and confidentiality that requires immediate attention to prevent unauthorized access to corporate information.
Remediation Plan
Immediate Action: As no official vendor patch is currently available, administrators should restrict network access to the /worksheet/del_work.jsp endpoint or disable the affected module entirely if it is not business critical.
Proactive Monitoring: Monitor web server logs for suspicious HTTP GET requests targeting the del_work.jsp file, specifically looking for payloads containing SQL syntax characters such as single quotes, semicolons, or comment indicators.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block incoming traffic containing SQL injection patterns directed at the KSOA application.
Exploitation Status
Public Exploit Available: Yes โ a published proof-of-concept exists, attributed to the technical write-up provided in the referenced GitHub issue.
Analyst Notes: As of January 20, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
Due to the availability of a public proof-of-concept and the lack of a vendor-provided security update, this vulnerability presents an elevated risk to the organization. Security teams must prioritize implementing network-level blocks or WAF rules to mitigate the threat until the vendor releases a formal patch for the affected KSOA component.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in Yonyou KSOA 9
A vulnerability has been found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: zhx123 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339363","name":"VDB-339363 | Yonyou KSOA work_edit.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339363","name":"VDB-339363 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721925","name":"Submit #721925 | Yonyou KSOA V1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/xinshou-test/CVE/issues/2","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to execute arbitrary SQL queries via the Report parameter in the /worksheet/work_edit.jsp file.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 exposes the application to unauthorized database access and potential system compromise by unauthenticated remote attackers.
Vulnerability Details
CVE-ID: CVE-2025-15436
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The application fails to sanitize the Report parameter within the /worksheet/work_edit.jsp file before incorporating it into SQL queries. This flaw allows an unauthenticated remote attacker to inject malicious SQL commands, resulting in a classic SQL injection vulnerability.
Business Impact
Successful exploitation of this vulnerability allows an attacker to bypass security controls to read, modify, or delete sensitive data stored in the backend database. Given the CVSS score of 7.3, this represents a significant risk to data confidentiality and integrity. If the database service account is overprivileged, an attacker could potentially achieve deeper system access, leading to unauthorized data exfiltration or service disruption, which poses a severe threat to business continuity.
Remediation Plan
Immediate Action: As no official vendor patch is currently available, restrict network access to the affected /worksheet/work_edit.jsp endpoint using firewall rules or Access Control Lists to prevent external reachability.
Proactive Monitoring: Review web server and database logs for anomalous input patterns, specifically looking for SQL syntax characters (e.g., quotes, semicolons, or comment indicators) within the Report parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads targeting the identified parameter.
Exploitation Status
Public Exploit Available: Yes โ a published proof-of-concept exists, attributed to the security researcher's technical write-up linked in the CVE references.
Analyst Notes: As of January 6, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of authentication requirements and the simple nature of the injection vector.
Analyst Recommendation
The presence of a publicly available proof-of-concept, combined with the unauthenticated nature of this vulnerability, makes it a high priority for remediation. Organizations using Yonyou KSOA 9.0 must implement immediate network-level restrictions to prevent unauthorized access to the vulnerable endpoint. Until the vendor releases a security update, continuous monitoring for exploitation attempts is essential to detect and block potential intrusion attempts.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in Yonyou KSOA 9
A flaw has been found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LNone (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339362","name":"VDB-339362 | Yonyou KSOA work_update.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339362","name":"VDB-339362 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721918","name":"Submit #721918 | Yonyou KSOA V1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/xiaozipang/CVE/issues/1","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to manipulate the Report parameter in the work_update.jsp file to execute arbitrary SQL commands.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to execute arbitrary database queries, posing a severe risk to system data and integrity.
Vulnerability Details
CVE-ID: CVE-2025-15435
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) located in the /worksheet/work_update.jsp file. An unauthenticated remote attacker can inject malicious SQL payloads via the Report GET parameter, which the application fails to sanitize before processing.
Business Impact
Successful exploitation allows unauthorized access to the underlying database, potentially leading to sensitive data exfiltration, unauthorized modification of records, or complete system compromise. With a CVSS score of 7.3, this flaw represents a significant risk to confidentiality and integrity, particularly for business-critical enterprise management systems.
Remediation Plan
Immediate Action: As no official vendor patch is currently available, administrators should immediately restrict network access to the vulnerable /worksheet/work_update.jsp endpoint or disable the affected module entirely if it is not business-critical.
Proactive Monitoring: Review web server access logs for anomalous GET requests targeting the work_update.jsp file, specifically looking for SQL-related patterns like WAITFOR DELAY, UNION, or SELECT statements.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block incoming HTTP requests containing SQL injection patterns directed at the /worksheet/work_update.jsp endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced GitHub repository.
Analyst Notes: As of January 3, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it requires zero authentication and targets a common database interaction pattern.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-provided patch, this vulnerability must be treated as a high priority. Organizations should immediately implement WAF filtering and internal network segmentation to isolate the KSOA instance until a formal security update is released by Yonyou.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Yonyou KSOA 9
A vulnerability was detected in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: yuxiu (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339361","name":"VDB-339361 | Yonyou KSOA PrintZPYG.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339361","name":"VDB-339361 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721490","name":"Submit #721490 | Yonyou KSOA V1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/cly-yuxiu/CVE/issues/1","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the zpjhid parameter in /kp/PrintZPYG.jsp.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 permits unauthenticated remote attackers to compromise the backend database.
Vulnerability Details
CVE-ID: CVE-2025-15434
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The application fails to properly sanitize the zpjhid parameter within the /kp/PrintZPYG.jsp file, enabling SQL injection. This flaw is exploitable by any unauthenticated attacker via a crafted GET request.
Business Impact
Successful exploitation grants an attacker the ability to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive corporate data, data exfiltration, or complete system compromise. With a CVSS score of 7.3, this vulnerability represents a significant risk to confidentiality and integrity, particularly for organizations relying on KSOA for core business processes.
Remediation Plan
Immediate Action: As no official patch is currently available from the vendor, restrict access to the /kp/PrintZPYG.jsp endpoint using network-level controls or a Web Application Firewall to block requests containing suspicious SQL syntax.
Proactive Monitoring: Review web server and database logs for anomalous GET requests targeting /kp/PrintZPYG.jsp, specifically looking for indicators of SQL injection such as UNION statements, time-based delays, or unexpected character sequences.
Compensating Controls: Deploy WAF rules designed to detect and block SQL injection patterns in URL parameters, and ensure the database service account is restricted to the minimum necessary privileges to limit the blast radius of a potential compromise.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to a researcher's technical write-up on GitHub.
Analyst Notes: As of January 3, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it requires zero authentication to execute.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-provided patch, organizations using Yonyou KSOA 9.0 must prioritize the implementation of compensating controls immediately. Network segmentation and strict input filtering are essential to defend against exploitation until a formal update is released by the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: jiefengliang (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339347","name":"VDB-339347 | Yonyou KSOA HTTP GET Parameter del_user.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339347","name":"VDB-339347 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721352","name":"Submit #721352 | Yonyou KSOA V9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://vuldb.com/?submit.734567","name":"Submit #734567 | Yonyou KSOA v9.0 SQL Injection (Duplicate)","tags":["third-party-advisory"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platform%20worksheet%20del_user.jsp%20SQL%20injection.md","name":null,"tags":["related"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platform%20worksheet%20del_user.jsp%20SQL%20injection.md#vulnerability-details-and-poc","name":null,"tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the /worksheet/del_user.jsp file, allowing unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to manipulate backend database queries, posing a severe risk to system integrity and data confidentiality.
Vulnerability Details
CVE-ID: CVE-2025-15425
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection (CWE-89) vulnerability occurring in the /worksheet/del_user.jsp file. An unauthenticated attacker can supply malicious input via the id HTTP GET parameter, which is concatenated into a SQL statement without proper sanitization or parameterization.
Business Impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary SQL commands against the backend Microsoft SQL Server database. This can lead to unauthorized data exfiltration, modification of sensitive records, or potential administrative compromise of the database server, significantly impacting the confidentiality and integrity of business operations. Given the CVSS score of 7.3, this flaw represents a significant risk to organizational security.
Remediation Plan
Immediate Action: As no official vendor patch is currently available, administrators should restrict network access to the affected /worksheet/del_user.jsp endpoint using firewall rules or network segmentation.
Proactive Monitoring: Review web server and database logs for anomalous request patterns, specifically looking for SQL syntax characters or time-based delay commands in the id parameter.
Compensating Controls: Deploy or update Web Application Firewall (WAF) signatures to detect and block common SQL injection payloads targeting the identified parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the linked research write-up.
Analyst Notes: As of January 5, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
The presence of a public proof-of-concept necessitates immediate defensive action to prevent potential exploitation. Because the vendor has not provided a patch, administrators must prioritize mitigating the exposure of the vulnerable endpoint. Implementing strict input validation or using a WAF to filter malicious traffic is critical until an official security update is released and applied.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: jiefengliang (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339346","name":"VDB-339346 | Yonyou KSOA HTTP GET Parameter agent_worksdel.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339346","name":"VDB-339346 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721348","name":"Submit #721348 | Yonyou KSOA V9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://vuldb.com/?submit.721526","name":"Submit #721526 | Yonyou KSOA V9.0 SQL Injection (Duplicate)","tags":["third-party-advisory"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksdel.jsp%20SQL%20injection.md","name":null,"tags":["related"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksdel.jsp%20SQL%20injection.md#vulnerability-details-and-poc","name":null,"tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter in the agent_worksdel.jsp file.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to compromise backend database integrity and confidentiality.
Vulnerability Details
CVE-ID: CVE-2025-15424
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) located in the /worksheet/agent_worksdel.jsp file. The application fails to sanitize the id HTTP GET parameter before concatenating it into a SQL query, allowing an unauthenticated attacker to inject malicious commands.
Business Impact
Successful exploitation of this vulnerability grants an attacker the ability to execute unauthorized SQL queries against the backend Microsoft SQL Server database. This can lead to full disclosure of sensitive organizational data, unauthorized modification or deletion of records, and potential escalation to administrative control over the database environment. With a CVSS score of 7.3, this flaw presents a significant risk to the confidentiality, integrity, and availability of business operations.
Remediation Plan
Immediate Action: As there is no official patch available, administrators must restrict network access to the affected endpoint or disable the vulnerable /worksheet/agent_worksdel.jsp file if it is not required for business operations.
Proactive Monitoring: Review web server and database logs for suspicious HTTP GET requests to the identified vulnerable path, specifically looking for SQL syntax patterns, time-based delay commands, or unusual character sequences in the id parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection attempts targeting the id parameter. Ensure that the database user account associated with the web application follows the principle of least privilege to limit the scope of potential damage.
Exploitation Status
Public Exploit Available: Yes, a functional proof-of-concept is available via the researcher's published write-up on GitHub.
Analyst Notes: As of January 3, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible to attackers as it requires no authentication to trigger.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-provided patch, this vulnerability poses an immediate risk to any exposed Yonyou KSOA 9.0 instances. Organizations should prioritize isolating the affected component and implementing robust WAF filtering to prevent exploitation until a formal security update is released by the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Yonyou KSOA 9
A vulnerability was detected in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: jiefengliang (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339343","name":"VDB-339343 | Yonyou KSOA HTTP GET Parameter agent_worksadd.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339343","name":"VDB-339343 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721324","name":"Submit #721324 | Yonyou KSOA V9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://vuldb.com/?submit.721527","name":"Submit #721527 | Yonyou KSOA V9.0 SQL Injection (Duplicate)","tags":["third-party-advisory"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksadd.jsp%20SQL%20injection.md","name":null,"tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.290Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter in the agent_worksadd.jsp file.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 exposes the backend database to unauthorized access and potential administrative compromise by unauthenticated remote attackers.
Vulnerability Details
CVE-ID: CVE-2025-15421
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the /worksheet/agent_worksadd.jsp file. The application fails to sanitize the id HTTP GET parameter before including it in database queries, allowing an unauthenticated attacker to manipulate backend SQL execution.
Business Impact
The exploitation of this vulnerability poses a severe threat to the confidentiality, integrity, and availability of the affected system. An attacker can achieve unauthorized database access, leak sensitive information, modify data, or potentially gain administrative control over the database server. With a CVSS score of 7.3, this flaw represents a significant risk to the business, as it allows for remote exploitation without the need for valid user credentials.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict network access to the affected /worksheet/agent_worksadd.jsp endpoint at the network or firewall level.
Proactive Monitoring: Review web server and database access logs for anomalous patterns, specifically looking for SQL injection syntax such as WAITFOR DELAY, UNION SELECT, or other database-specific commands targeting the id parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection attempts directed at the identified vulnerable endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the linked research write-up on GitHub.
Analyst Notes: As of January 3, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-provided patch, organizations running Yonyou KSOA 9.0 must treat this as a high-priority risk. Administrators should immediately implement compensating controls, such as strict WAF filtering, to block malicious requests. Until a vendor-supplied update is released and verified, assume that this endpoint is actively being probed by malicious actors.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Yonyou KSOA 9
A security vulnerability has been detected in Yonyou KSOA 9
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: jiefengliang (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.339342","name":"VDB-339342 | Yonyou KSOA agent_work_report.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.339342","name":"VDB-339342 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.721099","name":"Submit #721099 | Yonyou KSOA V9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://vuldb.com/?submit.721531","name":"Submit #721531 | Yonyou KSOA V9.0 SQL Injection (Duplicate)","tags":["third-party-advisory"]},{"url":"https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_work_report.jsp%20SQL%20injection.md","name":null,"tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:06.030Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 contains a SQL injection vulnerability in the /worksheet/agent_work_report.jsp file, allowing unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 enables unauthenticated remote attackers to compromise the underlying database.
Vulnerability Details
CVE-ID: CVE-2025-15420
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection (CWE-89) flaw located in the /worksheet/agent_work_report.jsp file. The application fails to sanitize the id parameter before concatenating it into a SQL query, allowing unauthenticated remote attackers to manipulate database operations.
Business Impact
The vulnerability poses a severe risk to the confidentiality, integrity, and availability of the affected system. Successful exploitation allows unauthorized database access, which may lead to sensitive data exfiltration, data tampering, or administrative control over the database server. While the CVSS score of 7.3 reflects the high risk of impact, the unauthenticated nature of the attack significantly elevates the urgency for remediation.
Remediation Plan
Immediate Action: As no official vendor patch is currently available, administrators should restrict network access to the /worksheet/agent_work_report.jsp endpoint to trusted internal networks only.
Proactive Monitoring: Review web and database access logs for anomalous requests containing SQL syntax patterns such as WAITFOR DELAY or stacked query indicators.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block SQL injection attempts targeting the id parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.
Analyst Notes: As of January 5, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of required authentication.
Analyst Recommendation
Given the public availability of exploit details and the absence of a vendor-provided patch, organizations running Yonyou KSOA 9.0 must treat this as a high-priority risk. Implement strict WAF filtering and network-level access controls immediately to prevent unauthorized exploitation. Monitor for official vendor guidance and apply security updates as soon as they become available.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Yonyou KSOA 9.0 is vulnerable to unauthenticated arbitrary file uploads via the ImageUpload servlet, allowing remote attackers to execute arbitrary co...
Yonyou KSOA 9.0 is vulnerable to unauthenticated arbitrary file uploads via the ImageUpload servlet, allowing remote attackers to execute arbitrary code by uploading malicious JSP files.
---METADATA---
VENDOR: Yonyou Network Technology Co.
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 is vulnerable to unauthenticated arbitrary file uploads via the ImageUpload servlet, allowing remote attackers to execute arbitrary code by uploading malicious JSP files.
Executive Summary:
An unauthenticated remote code execution vulnerability in Yonyou KSOA 9.0 poses a critical risk to organizational systems due to confirmed active exploitation in the wild.
Vulnerability Details
CVE-ID: CVE-2022-50973
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: The application fails to perform authentication or file validation within the com.sksoft.bill.ImageUpload servlet. Unauthenticated attackers can upload and execute arbitrary JSP webshells by manipulating filepath and filename parameters.
Business Impact
With a CVSS score of 9.8, this vulnerability represents an extreme risk, enabling full system compromise. Successful exploitation grants attackers persistent access to the underlying server, potentially leading to total data exfiltration, lateral movement within the internal network, and severe reputational damage.
Remediation Plan
Immediate Action: Update Yonyou KSOA to the latest patched version provided by the vendor immediately, as exploitation is confirmed to be occurring in the wild.
Proactive Monitoring: Inspect web server logs for suspicious POST requests directed at the ImageUpload servlet and search for unauthorized JSP files within the /pictures/ directory.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block requests containing suspicious filename extensions or path traversal characters directed at the identified servlet.
Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Jul 2, 2026, there is confirmed evidence that this vulnerability is being actively exploited in the wild. The critical nature of this flaw necessitates an immediate emergency patching cycle.
Analyst Recommendation
Given the confirmed active exploitation and the high severity of this remote code execution vulnerability, administrators must prioritize this update above all other maintenance tasks. Failure to remediate could result in a complete compromise of the hosting server and surrounding network infrastructure.
Update Yonyou Network Technology Co. KSOA to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Yonyou
PRODUCT: KSOA
AFFECTED_VERSIONS: 9.0
CONFIDENCE: high
MISSING: patch
CREDITS: LINXI666 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/?id.341773","name":"VDB-341773 | Yonyou KSOA HTTP GET Parameter user_popedom.jsp sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.341773","name":"VDB-341773 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.734594","name":"Submit #734594 | Yonyou KSOA v9.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/LX-66-LX/cve/issues/19","name":null,"tags":["exploit","issue-tracking"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:04.758Z
---END_METADATA---
Description Summary:
Yonyou KSOA 9.0 is vulnerable to a remote SQL injection attack via the folderid parameter in the user_popedom.jsp file.
Executive Summary:
A critical SQL injection vulnerability in Yonyou KSOA 9.0 allows unauthenticated remote attackers to manipulate database queries, posing a significant risk of unauthorized data access.
Vulnerability Details
CVE-ID: CVE-2026-1179
Affected Software: Yonyou KSOA
Affected Versions: 9.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) triggered by the improper sanitization of the folderid HTTP GET parameter within the /kmf/user_popedom.jsp component. The vulnerability is remotely exploitable without requiring authentication.
Business Impact
The vulnerability carries a CVSS score of 7.3, indicating a high severity risk that could lead to unauthorized data exposure or manipulation within the affected system. Exploitation may result in severe business disruption, theft of sensitive corporate data, and potential compromise of the underlying database integrity.
Remediation Plan
Immediate Action: Given the lack of a vendor patch, restrict network access to the /kmf/user_popedom.jsp endpoint at the network or application firewall level until the manufacturer provides an official update.
Proactive Monitoring: Monitor web application logs for suspicious GET requests containing SQL syntax or unusual characters within the folderid parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block or sanitize input targeting the folderid parameter in the identified JSP file.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub issue.
Analyst Notes: As of January 21, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
The presence of a public proof-of-concept combined with the unauthenticated nature of this flaw elevates the risk to the organization. Administrators must prioritize blocking access to the vulnerable endpoint immediately and continue monitoring vendor channels for the release of an official security update. Failure to implement mitigating controls leaves the application exposed to potential data exfiltration.