CVE-2025-15421 | Yonyou KSOA 9.0 HTTP GET Parameter agent_worksadd.jsp ID sql injection (EUVD-2026-0720)
A vulnerability labeled as critical has been found in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2025-15421. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.