SQL Injection Vulnerability in Yonyou KSOA 9.0 Affects Remote Systems
CVE-2025-15425
Key Information:
Badges
What is CVE-2025-15425?
A SQL injection vulnerability exists in Yonyou KSOA 9.0 due to improper handling of input parameters in the del_user.jsp file. An attacker can exploit this vulnerability remotely by manipulating the ID parameter in HTTP GET requests. The potential for unauthorized database access through this flaw is significant, as it may allow an attacker to view, modify, or delete sensitive data. This vulnerability has been publicly disclosed, and attempts to notify the vendor have gone unanswered.
Affected Version(s)
KSOA 9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
