CVE-2026-1177: Yonyou KSOA HTTP GET Parameter save_folder.jsp sql injection
A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/savefolder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1177?
CVE-2026-1177 has been classified with a high severity due to its potential for SQL injection.
How do I fix CVE-2026-1177?
To fix CVE-2026-1177, ensure that all input parameters are properly sanitized and use prepared statements to prevent SQL injection attacks.
Which versions of Yonyou KSOA are affected by CVE-2026-1177?
CVE-2026-1177 affects Yonyou KSOA version 9.0.
What type of vulnerability is CVE-2026-1177?
CVE-2026-1177 is classified as an SQL injection vulnerability that can be exploited through the HTTP GET parameter in save_folder.jsp.
What is the impact of exploiting CVE-2026-1177?
Exploiting CVE-2026-1177 can allow an attacker to manipulate SQL queries, potentially leading to unauthorized data access or data manipulation.