CVE-2015-20122: Yonyou a6 Oa
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.
Affected products
- Yonyou a6 Oa: any version
Published 2026-09-29. Last modified 2026-09-30.