MEDIUM
Yonyou KSOA HTTP GET Parameter work_report.jsp sql injection
Published Jan 18, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.46%
Description
A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3173 Advisory
- https://github.com/LX-66-LX/cve/issues/10 exploitissue-trackingBroken Link
- https://vuldb.com/?ctiid.341716 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.341716 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.734551 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3173 | Advisory | |
| https://github.com/LX-66-LX/cve/issues/10 | exploitissue-trackingBroken Link | |
| https://vuldb.com/?ctiid.341716 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.341716 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.734551 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 18, 2026
Updated Feb 23, 2026
Reserved Jan 17, 2026
Link CVE-2026-1124
CISA Vulnrichment
Updated Jan 20, 2026
Red Hat
No data
GitHub
No data