CVE-2026-94491 | Yonyou KSOA 9.0 search_list.jsp address sql injection

SecurityVulns

A vulnerability was found in Yonyou KSOA 9.0. It has been declared as critical. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection.

This vulnerability is registered as CVE-2026-94491. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More