CVE-2026-1131: Yonyou KSOA HTTP GET Parameter save_catalog.jsp sql injection
A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/savecatalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1131?
CVE-2026-1131 is classified as a critical vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2026-1131?
To fix CVE-2026-1131, ensure that user input is properly validated and sanitized to prevent SQL injection.
What type of attack can CVE-2026-1131 facilitate?
CVE-2026-1131 can facilitate SQL injection attacks, allowing attackers to manipulate database queries.
Which software is affected by CVE-2026-1131?
CVE-2026-1131 affects Yonyou KSOA version 9.0.
What component is vulnerable in CVE-2026-1131?
The vulnerable component in CVE-2026-1131 is the HTTP GET Parameter Handler in the file /kmc/save_catalog.jsp.