CVE-2015-20122
Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.
| CWE | CWE-89 |
| Vendor | yonyou |
| Product | a6 oa |
| Published | Sep 29, 2026 |
| Last Updated | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for yonyou a6 oa
Be the first to know when new high vulnerabilities affecting yonyou a6 oa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Yonyou / A6 OA
*
References
Credits
๐ The Shadowserver Foundation