Product
Yonyou KSOA 9.0 is vulnerable to unauthenticated remote SQL injection via the address argument in the /cardcase/search_list.jsp endpoint.