CVE-2026-1131 | Yonyou KSOA 9.0 HTTP GET Parameter /kmc/save_catalog.jsp catalogid sql injection
A vulnerability categorized as critical has been discovered in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection.
This vulnerability is referenced as CVE-2026-1131. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.