CVE-2026-1121 | Yonyou KSOA 9.0 HTTP GET Parameter del_workplan.jsp ID sql injection (EUVD-2026-3174)
A vulnerability classified as critical was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2026-1121. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.