{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ksoa-9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yonyou:ksoa:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94491"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KSOA (9.0)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Yonyou"],"content_html":"\u003cp\u003eCVE-2026-94491 is a critical SQL injection vulnerability discovered in Yonyou KSOA 9.0. The vulnerability resides within the /cardcase/search_list.jsp file, where the address argument fails to properly sanitize user-supplied input. An unauthenticated remote attacker can leverage this flaw to inject arbitrary SQL commands, potentially leading to unauthorized data exfiltration or modification within the application database. Public proof-of-concept exploit code is currently available, significantly increasing the risk of exploitation. As of the current disclosure date, the vendor has not responded to vulnerability reports or issued a security patch, leaving deployments exposed. Defenders should restrict network access to the affected web application components and monitor logs for anomalous SQL syntax patterns associated with this specific URI.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-94491 grants an attacker the ability to execute unauthorized database queries. This can lead to full compromise of the KSOA application database, resulting in the exfiltration of sensitive organizational data, manipulation of business records, or potential further compromise of the underlying server infrastructure if database permissions are misconfigured. Given the lack of a vendor patch, the impact remains elevated for all organizations utilizing Yonyou KSOA 9.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for requests to /cardcase/search_list.jsp containing SQL injection payloads within the address parameter.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to block suspicious HTTP requests targeting the /cardcase/search_list.jsp endpoint with typical SQL injection indicators (e.g., UNION, SELECT, OR, SLEEP).\u003c/li\u003e\n\u003cli\u003eIsolate the Yonyou KSOA application from the public internet if it does not require external access, or restrict access via IP whitelisting to known trusted networks.\u003c/li\u003e\n\u003cli\u003eEngage with the vendor's support channels to pressure the release of an official security update.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T02:32:23Z","date_published":"2026-09-22T02:32:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yonyou-ksoa-sqli/","summary":"Yonyou KSOA 9.0 is vulnerable to unauthenticated remote SQL injection via the address argument in the /cardcase/search_list.jsp endpoint.","title":"CVE-2026-94491 SQL Injection in Yonyou KSOA","url":"https://feed.craftedsignal.io/briefs/2026-09-yonyou-ksoa-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - KSOA (9.0)","version":"https://jsonfeed.org/version/1.1"}