PT-2026-3414 · Yonyou · Yonyou Ksoa 9.0

Lx-66-Lx

·

Published

2026-01-19

·

Updated

2026-02-10

·

CVE-2026-1131

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yonyou KSOA version 9.0
Description A SQL injection issue exists due to manipulation of the catalogid parameter in the HTTP GET request to the /kmc/save catalog.jsp file. This affects an unknown function within the HTTP GET Parameter Handler component. The issue is remotely exploitable and the exploit details have been publicly disclosed. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1131

Affected Products

Yonyou Ksoa 9.0