Weaver E-cology是中国Weaver公司的一个企业管理协作平台。 Weaver E-cology 8.0版本和9.0版本存在SQL注入漏洞,该漏洞源于HrmCareerApplyPerView.jsp端点对id GET参数未进行充分过滤,存在SQL注入漏洞,可能导致未经身份验证的远程攻击者从后端数据库提取任意数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology 8.0 | < 10.53 |
affected |
< 10.54 |
affected | ||
| Weaver Network Co., Ltd. | E-cology 9.0 | < 10.53 |
affected |
< 10.54 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Weaver Network Co., Ltd. | E-cology 9.0 | 0 ~ 10.53 | - |
|
| Weaver Network Co., Ltd. | E-cology 8.0 | 0 ~ 10.53 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet