SQL Injection Vulnerability in Yonyou KSOA 9.0
CVE-2026-94491
6.9MEDIUM
What is CVE-2026-94491?
A vulnerability has been detected in Yonyou KSOA 9.0, specifically affecting the file /cardcase/search_list.jsp. By manipulating the address argument, an attacker can perform SQL injection, which may lead to unauthorized data access or manipulation. This vulnerability is exploitable remotely and poses a significant risk given that details have been released publicly, enabling potential attacks. The vendor has been made aware of this issue but has not responded to the disclosure.
Affected Version(s)
KSOA 9.0
