CVE-2026-1129 | Yonyou KSOA 9.0 HTTP GET Parameter /worksheet/worksadd.jsp ID sql injection
A vulnerability was found in Yonyou KSOA 9.0. It has been declared as critical. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection.
This vulnerability was named CVE-2026-1129. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.