PatchSiren cyber security CVE debrief
CVE-2025-15421 Yonyou CVE debrief
A SQL injection vulnerability was detected in Yonyou KSOA 9.0, affecting the file /worksheet/agent_worksadd.jsp. The vulnerability is triggered by manipulating the ID argument in an HTTP GET request. This issue allows remote attackers to inject malicious SQL. The exploit is public, and although the vendor was notified, no response was received. The vulnerability can be exploited remotely, and defenders should assess their exposure and monitor for suspicious activity related to Yonyou KSOA 9.0 systems.
- Vendor
- Yonyou
- Product
- KSOA
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-02
- Original CVE updated
- 2026-10-01
- Advisory published
- 2026-01-02
- Advisory updated
- 2026-10-01
Who should care
Defenders of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, should assess their exposure and monitor for suspicious activity related to SQL injection attacks. They should verify exposure of Yonyou KSOA 9.0 systems, assess potential impact, and prioritize patching or mitigating vulnerable systems. Security teams and operators managing Yonyou KSOA 9.0 should review the supplied official advisory or CVE record to validate affected scope, and
Why it matters
This SQL injection vulnerability in Yonyou KSOA 9.0 allows remote attackers to inject malicious SQL, potentially leading to data breaches or system compromise. Defenders should verify exposure, assess potential impact, and prioritize patching or mitigating vulnerable systems.
- Verify exposure of Yonyou KSOA 9.0 systems to SQL injection attacks
- Assess potential impact of successful SQL injection attacks
- Monitor for suspicious HTTP GET requests to /worksheet/agent_worksadd.jsp
- Prioritize patching or mitigating vulnerable systems
Technical summary
The vulnerability is located in the /worksheet/agent_worksadd.jsp file of Yonyou KSOA 9.0. It is triggered by manipulating the ID argument in an HTTP GET request, allowing for SQL injection attacks. This issue allows remote attackers to inject malicious SQL, potentially leading to data breaches or system compromise. Defenders should verify exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks. The exploit is public, and although the vendor was notified, no response was received.
Defensive priority
Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks.
Recommended defensive actions
- Verify exposure of Yonyou KSOA 9.0 systems
- Assess for potential SQL injection attacks
- Monitor for suspicious HTTP GET requests to /worksheet/agent_worksadd.jsp
- Prioritize patching or mitigating vulnerable systems
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability. A public exploit exists, but details are limited. Defenders should verify exposure of Yonyou KSOA 9.0 systems, especially those accessible via HTTP, and assess for potential SQL injection attacks. The source-provided information indicates a SQL injection vulnerability in the /worksheet/agent_worksadd.jsp file of Yonyou KSOA 9.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15421 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15421
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15421 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15421
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksadd.jsp%20SQL%20injection.md
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.