CVE-2026-94491
7.3 HIGHPublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw is a SQL injection vulnerability in Yonyou KSOA 9.0 due to improper argument handling in search_list.jsp, allowing remote attackers to execute arbitrary SQL commands. This matters because it can lead to data theft or corruption.
- Exploitability
- Exploitation requires manipulation of the 'address' argument and access to the application. The vulnerability is remotely exploitable but specific conditions must be met for successful injection.
- Blast radius
- If exploited, this could result in unauthorized data access or modification across the affected system, potentially impacting multiple users and services.
- Prioritized remediation
- Apply vendor patches or update search_list.jsp to properly sanitize input parameters and prevent SQL injection attacks.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-74, CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-18854
- HIGHCVE-2026-94144PoC
- MEDIUMCVE-2026-94492PoC
- MEDIUMCVE-2026-15941
- HIGHCVE-2026-70369
- HIGHCVE-2026-70370
- HIGHCVE-2026-70371
- HIGHCVE-2026-70372
Related by shared AI tags and CWE weakness class. Browse the full archive.