VYPR

KSOA Platform

by Yonyou

CVEs (2)

  • CVE-2025-15425HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed…

  • CVE-2025-15420HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and…