PatchSiren cyber security CVE debrief
CVE-2025-15435 Yonyou CVE debrief
A SQL injection vulnerability exists in Yonyou KSOA 9.0, specifically in the /worksheet/work_update.jsp file when manipulating the Report argument. This issue allows for remote attacks and has been publicly disclosed. The vendor, Yonyou, was notified but did not respond. Defenders should assess exposure and verify security controls against SQL injection attacks. This vulnerability has a CVSS score of 5.5, indicating medium severity. The exploit has been published and may be used. Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, are affected.
- Vendor
- Yonyou
- Product
- KSOA
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-02
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-02
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, should assess exposure and verify the effectiveness of current security controls against SQL injection attacks.
Why it matters
CVE-2025-15435 is a SQL injection vulnerability in Yonyou KSOA 9.0 that allows for remote attacks. Defenders should prioritize verifying exposure and assessing the effectiveness of current security controls.
- Verify exposure of Yonyou KSOA 9.0 systems to SQL injection attacks
- Assess the effectiveness of current security controls against remote attacks
- Implement input validation and sanitization for user-supplied input
- Monitor for suspicious activity and implement logging and auditing
Technical summary
The vulnerability exists in the /worksheet/work_update.jsp file of Yonyou KSOA 9.0, allowing for remote SQL injection attacks through manipulation of the Report argument. The CVSS score is 5.5, indicating a medium severity. This issue was publicly disclosed, and the exploit has been published. Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, and assess the effectiveness of current security controls against SQL injection attacks. Input validation and sanitization for user-supplied input should be implemented, and monitoring for suspicious activity with logging and auditing is recommended.
Defensive priority
Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, and assess the effectiveness of current security controls against SQL injection attacks.
Recommended defensive actions
- Verify exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp
- Assess the effectiveness of current security controls against SQL injection attacks
- Implement input validation and sanitization for user-supplied input
- Monitor for suspicious activity and implement logging and auditing
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score of 5.5 and the fact that it allows for remote SQL injection attacks. However, details on affected versions, exploitation, and remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15435 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15435
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15435 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15435
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xiaozipang/CVE/issues/1
[email protected] - Exploit, Issue Tracking, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.