CVE-2024-24256: Yonyou

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.

Affected products

  • Yonyou Yonyou: up to and including 9.0

Published 2024-02-15. Last modified 2026-06-17.