CVE-2022-50992

HIGH EXPLOITED

Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2022-50992 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).

Scores

CVSS v3 7.5
EPSS 0.0070
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-04-30
CWE
CWE-22
Status published
Products (1)
Weaver Network Co., Ltd./E-cology < 10.52
Published Apr 30, 2026
Tracked Since Apr 30, 2026