SQL Injection Vulnerability in Yonyou KSOA 9.0
CVE-2026-94491

6.9MEDIUM

Key Information:

Vendor

Yonyou

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-94491?

A vulnerability has been detected in Yonyou KSOA 9.0, specifically affecting the file /cardcase/search_list.jsp. By manipulating the address argument, an attacker can perform SQL injection, which may lead to unauthorized data access or manipulation. This vulnerability is exploitable remotely and poses a significant risk given that details have been released publicly, enabling potential attacks. The vendor has been made aware of this issue but has not responded to the disclosure.

Affected Version(s)

KSOA 9.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mjh_123 (VulDB User)
VulDB CNA Team
.