CVE-2026-1120 | Yonyou KSOA 9.0 HTTP GET Parameter /worksheet/del_work.jsp ID sql injection
A vulnerability classified as critical has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID leads to sql injection.
This vulnerability is documented as CVE-2026-1120. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.