RULE(RULE ID:339127)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou KSOA linkadd.jsp SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A critical SQL injection vulnerability exists in the fillKP.jsp interface of Yonyou KSOA system. Unauthenticated attackers can inject malicious SQL queries via user-controllable inputs, enabling direct manipulation of backend databases and theft of administrative credentials/core business data. This flaw stems from unsafe dynamic query concatenation without input sanitization.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.