CVE-2022-4995
CRITICAL EXPLOITEDWeaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
Title source: cnaExploitation Summary
CVE-2022-4995 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).
References (6)
Core 6
Core References
Release Notes release-notes
https://www.weaver.com.cn/cs/ecology_full_log_en.html
Third Party Advisory third-party-advisory
https://cn-sec.com/archives/1208148.html
Exploit technical-description
exploit
https://ch0x01e.github.io/post/ecology9-wen-jian-shang-chuan-fen-xi/
Exploit technical-description
exploit
https://github.com/gmh5225/CVE-2022-HW-POC/blob/main/%E6%B3%9B%E5%BE%AEOA%20uploaderOperate.jsp%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/weaver-e-cology-file-upload-rce-via-uploaderoperate-jsp
Scores
CVSS v3
9.8
EPSS
0.0069
EPSS Percentile
49.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2023-10-14
CWE
CWE-434
Status
published
Products (1)
Weaver Network Co., Ltd./E-cology 9.0
< 10.52
Published
Aug 07, 2026
Tracked Since
Aug 07, 2026