PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15421 Yonyou CVE debrief

A SQL injection vulnerability was detected in Yonyou KSOA 9.0, affecting the file /worksheet/agent_worksadd.jsp. The vulnerability is triggered by manipulating the ID argument in an HTTP GET request. This issue allows remote attackers to inject malicious SQL. The exploit is public, and although the vendor was notified, no response was received. The vulnerability can be exploited remotely, and defenders should assess their exposure and monitor for suspicious activity related to Yonyou KSOA 9.0 systems.

Vendor
Yonyou
Product
KSOA
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-10-01
Advisory published
2026-01-02
Advisory updated
2026-10-01

Who should care

Defenders of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, should assess their exposure and monitor for suspicious activity related to SQL injection attacks. They should verify exposure of Yonyou KSOA 9.0 systems, assess potential impact, and prioritize patching or mitigating vulnerable systems. Security teams and operators managing Yonyou KSOA 9.0 should review the supplied official advisory or CVE record to validate affected scope, and

Why it matters

This SQL injection vulnerability in Yonyou KSOA 9.0 allows remote attackers to inject malicious SQL, potentially leading to data breaches or system compromise. Defenders should verify exposure, assess potential impact, and prioritize patching or mitigating vulnerable systems.

  • Verify exposure of Yonyou KSOA 9.0 systems to SQL injection attacks
  • Assess potential impact of successful SQL injection attacks
  • Monitor for suspicious HTTP GET requests to /worksheet/agent_worksadd.jsp
  • Prioritize patching or mitigating vulnerable systems

Technical summary

The vulnerability is located in the /worksheet/agent_worksadd.jsp file of Yonyou KSOA 9.0. It is triggered by manipulating the ID argument in an HTTP GET request, allowing for SQL injection attacks. This issue allows remote attackers to inject malicious SQL, potentially leading to data breaches or system compromise. Defenders should verify exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks. The exploit is public, and although the vendor was notified, no response was received.

Defensive priority

Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks.

Recommended defensive actions

  • Verify exposure of Yonyou KSOA 9.0 systems
  • Assess for potential SQL injection attacks
  • Monitor for suspicious HTTP GET requests to /worksheet/agent_worksadd.jsp
  • Prioritize patching or mitigating vulnerable systems
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability. A public exploit exists, but details are limited. Defenders should verify exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks. The source-provided information indicates a SQL injection vulnerability in the /worksheet/agent_worksadd.jsp file of Yonyou KSOA 9.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15421 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15421

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15421 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15421

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksadd.jsp%20SQL%20injection.md

    [email protected] - Exploit, Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.