VYPR

space-time enterprise information integration platform

by Yonyou

CVEs (2)

  • CVE-2025-15424HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the…

  • CVE-2024-24256MedFeb 15, 2024
    risk 0.38cvss 5.9epss 0.00

    SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.