Executive brief
Yonyou KSOA is a business process management suite used by enterprises. A SQL injection vulnerability in the search_list.jsp component allows remote attackers to manipulate the address parameter and execute arbitrary SQL commands, potentially exposing or modifying sensitive business data. The vulnerability is publicly disclosed and exploit code is available.
Technical details
SQL injection vulnerability in /cardcase/search_list.jsp allows an unauthenticated remote attacker to execute arbitrary SQL queries by manipulating the address parameter. The vulnerability is network-accessible with no authentication required, enabling attackers to exfiltrate database contents or modify data. A fix status is unknown as the vendor did not respond to disclosure.
Affected products
- Yonyou KSOA 9.0
Timeline
- 2026-09-22: disclosed