CVE-2025-15420 | Yonyou KSOA 9.0 agent_work_report.jsp ID sql injection (EUVD-2026-0719)
A vulnerability identified as critical has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection.
This vulnerability is documented as CVE-2025-15420. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.