Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2022-4995: Weaver E-cology 9.0 allows unauthorized file uploads
CVE-2022-4995 · published 28 days ago
Summary
Weaver E-cology versions 9.0 to 10.51 are vulnerable to a file upload security risk. This means an attacker can upload malicious files without permission, potentially allowing them to take control of your server. Update to version 10.52 or later to fix this issue.
What to do
- Update weaver network co., ltd. e-cology 9.0 to version 10.52 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| weaver network co., ltd. | e-cology 9.0 | < 10.52 |
Original advisory text
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).
References
- https://ch0x01e.github.io/post/ecology9-wen-jian-shang-chuan-fen-xi/
- https://cn-sec.com/archives/1208148.html
- https://github.com/gmh5225/CVE-2022-HW-POC/blob/main/%E6%B3%9B%E5%BE%AEOA%20uplo...
- https://www.weaver.com.cn/cs/ecology_full_log_en.html
- https://www.weaver.com.cn/cs/securityDownload.html#
- https://www.vulncheck.com/advisories/weaver-e-cology-file-upload-rce-via-uploade... third-party-advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published7 Aug 2026
Updated3 Sep 2026
First seen7 Aug 2026
Monitor software like this
Free during beta