VYPR

Ksoa

by Yonyou

CVEs (22)

  • CVE-2025-15420HigJan 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and…

  • CVE-2022-50973CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.02

    Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters…

Page 2 of 2