RULE(RULE ID:339165)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou OA CheckLogin SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yonyou OA is an enterprise office automation software, which can help enterprises realize electronic office and provide a collaborative office portal and management platform for enterprises and institutions.The link interface in Yonyou OA contains an SQL injection vulnerability, which can be exploited by attackers to obtain sensitive data.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.