---
id: CVE-2025-15421
title: A vulnerability was detected in Yonyou KSOA 9.0
summary: >-
  A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects
  unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP
  GET Parameter Handler. The manipulation of the argument ID results in sql
  injection.…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: yonyou
product: ksoa
affected:
  - ksoa = 9.0
published: '2026-01-02'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15421'
references:
  - url: >-
      https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksadd.jsp%20SQL%20injection.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.339343'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.339343'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.721324'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.721527'
    label: cna@vuldb.com
  - url: >-
      https://github.com/master-abc/cve/blob/main/Yonyou%20Space-Time%20Enterprise%20Information%20Integration%20KSOA%20Platformworksheetagent_worksadd.jsp%20SQL%20injection.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00456
epssPercentile: 0.37123
ingestedAt: '2026-10-01T08:40:11.727Z'
---

## Overview

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `ksoa = 9.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
