CVE-2026-1179: Yonyou KSOA HTTP GET Parameter user_popedom.jsp sql injection
A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/userpopedom.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument folderid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1179?
CVE-2026-1179 is considered to have a high severity due to its exploitation potential via SQL injection.
How do I fix CVE-2026-1179?
To fix CVE-2026-1179, it is recommended to validate and sanitize HTTP GET parameters before processing them in the application.
What is affected by CVE-2026-1179?
CVE-2026-1179 affects Yonyou KSOA version 9.0, specifically the user_popedom.jsp file.
What types of attacks can CVE-2026-1179 enable?
CVE-2026-1179 can enable SQL injection attacks, allowing unauthorized access to the database.
Is there a workaround for CVE-2026-1179?
A potential workaround for CVE-2026-1179 includes employing web application firewalls to filter malicious input.