PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15435 Yonyou CVE debrief

A SQL injection vulnerability exists in Yonyou KSOA 9.0, specifically in the /worksheet/work_update.jsp file when manipulating the Report argument. This issue allows for remote attacks and has been publicly disclosed. The vendor, Yonyou, was notified but did not respond. Defenders should assess exposure and verify security controls against SQL injection attacks. This vulnerability has a CVSS score of 5.5, indicating medium severity. The exploit has been published and may be used. Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, are affected.

Vendor
Yonyou
Product
KSOA
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-09-30
Advisory published
2026-01-02
Advisory updated
2026-09-30

Who should care

Defenders responsible for Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, should assess exposure and verify the effectiveness of current security controls against SQL injection attacks.

Why it matters

CVE-2025-15435 is a SQL injection vulnerability in Yonyou KSOA 9.0 that allows for remote attacks. Defenders should prioritize verifying exposure and assessing the effectiveness of current security controls.

  • Verify exposure of Yonyou KSOA 9.0 systems to SQL injection attacks
  • Assess the effectiveness of current security controls against remote attacks
  • Implement input validation and sanitization for user-supplied input
  • Monitor for suspicious activity and implement logging and auditing

Technical summary

The vulnerability exists in the /worksheet/work_update.jsp file of Yonyou KSOA 9.0, allowing for remote SQL injection attacks through manipulation of the Report argument. The CVSS score is 5.5, indicating a medium severity. This issue was publicly disclosed, and the exploit has been published. Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, and assess the effectiveness of current security controls against SQL injection attacks. Input validation and sanitization for user-supplied input should be implemented, and monitoring for suspicious activity with logging and auditing is recommended.

Defensive priority

Defenders should prioritize verifying exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp, and assess the effectiveness of current security controls against SQL injection attacks.

Recommended defensive actions

  • Verify exposure of Yonyou KSOA 9.0 systems, especially those with internet-facing /worksheet/work_update.jsp
  • Assess the effectiveness of current security controls against SQL injection attacks
  • Implement input validation and sanitization for user-supplied input
  • Monitor for suspicious activity and implement logging and auditing
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score of 5.5 and the fact that it allows for remote SQL injection attacks. However, details on affected versions, exploitation, and remediation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15435 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15435

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15435 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15435

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.