Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2022-4995: Weaver E-cology 9.0 allows unauthorized file uploads

CVE-2022-4995
Summary

Weaver E-cology versions 9.0 to 10.51 are vulnerable to a file upload security risk. This means an attacker can upload malicious files without permission, potentially allowing them to take control of your server. Update to version 10.52 or later to fix this issue.

Original title
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submit...
Original description
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026