{"id":"CVE-2026-94491","published":"2026-09-22T01:16:56.077","lastModified":"2026-09-22T01:16:56.077","description":"A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-74","CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-94491","tags":[]},{"url":"https://vuldb.com/submit/895364","tags":[]},{"url":"https://vuldb.com/vuln/408191","tags":[]},{"url":"https://vuldb.com/vuln/408191/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a SQL injection vulnerability in Yonyou KSOA 9.0 due to improper argument handling in search_list.jsp, allowing remote attackers to execute arbitrary SQL commands. This matters because it can lead to data theft or corruption.","exploitability":"Exploitation requires manipulation of the 'address' argument and access to the application. The vulnerability is remotely exploitable but specific conditions must be met for successful injection.","blast_radius":"If exploited, this could result in unauthorized data access or modification across the affected system, potentially impacting multiple users and services.","remediation":"Apply vendor patches or update search_list.jsp to properly sanitize input parameters and prevent SQL injection attacks.","tags":["sql-injection","web","rce","remote-exploit","patch"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:16:44.529Z"}}