Weaver Network Co., Ltd. Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Weaver Network Co., Ltd. products.
Products
- E-cology2 vulnerabilities
- E-cology 8.02 vulnerabilities
- E-cology 9.02 vulnerabilities
- E-office1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-50997HIGH | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jspWeaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software ver… CWE-89Aug 11, 2026 | CVSS8.7v4.0 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-20097HIGH | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoadWeaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path, causing the servlet to read and stream back arbitrary files accessible to the application server p… CWE-89Aug 11, 2026 | CVSS8.7v4.0 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4995CRITICAL | Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jspWeaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shado… CWE-434Aug 7, 2026 | CVSS9.3v4.0 | EPSS0.687% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-50992HIGH | Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServletWeaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Explo… CWE-22Apr 30, 2026 | CVSS8.7v4.0 | EPSS0.705% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-50993CRITICAL | Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServletWeaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by th… CWE-434Apr 30, 2026 | CVSS9.3v4.0 | EPSS0.774% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22679CRITICAL | Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug EndpointWeaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first ob… CWE-306Apr 7, 2026 | CVSS9.3v4.0 | EPSS21.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |