
CVE-2022-50973 Yonyou KSOA ERP Tier 1: unauthenticated file upload lets attackers deploy webshells and execute code on internet-facing ERP systems, with confirmed in-the-wild exploitation Full Analysis https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-02/TIER_1_CVE-2022-50973.md #CyberSecurity #VulnerabilityManagement #CyberRisk
Post summary
CVE-2022-50973 is actively exploited via an unauthenticated file upload flaw that allows attackers to deploy webshells and execute code on Yonyou KSOA ERP systems; a detailed analysis is available in the linked report.



