CVE-2022-50997
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp
Record summary
CVE-2022-50997 has a selected CVSS score of 8.7 (high).
Description
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software version 10.53 or 10.54. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 11, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
E-cology 8.0Browse Weaver Network Co., Ltd. / E-cology 8.0Default status: affected | CVE List | Before 10.53 | unknown |
| Before 10.54 | unknown | ||
E-cology 9.0Browse Weaver Network Co., Ltd. / E-cology 9.0Default status: affected | CVE List, VulnCheck | Before 10.53 | unknown |
| Before 10.54 | unknown |