VYPR

Ksoa

by Yonyou

CVEs (20)

  • CVE-2026-1179HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument folderid results in sql injection. The attack can be launched remotely. The exploit is…

  • CVE-2026-1178HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /kmf/select.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument folderid leads to sql injection. The attack can be…

  • CVE-2026-1177HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. It is possible…

  • CVE-2026-1133HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. The attack can be launched…

  • CVE-2026-1132HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid results in sql injection. The attack can be initiated…

  • CVE-2026-1131HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-1130HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely.…

  • CVE-2026-1129HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The…

  • CVE-2026-1124HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote…

  • CVE-2026-1123HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is…

  • CVE-2026-1122HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2026-1121HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has…

  • CVE-2026-1120HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-15436HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…

  • CVE-2025-15435HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and…

  • CVE-2025-15434HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor…

  • CVE-2025-15425HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_user.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed…

  • CVE-2025-15424HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_worksdel.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the…

  • CVE-2025-15421HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The…

  • CVE-2025-15420HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and…