RULE(RULE ID:337506)

Rule General Information
Release Date: 2023-05-25
Rule Name: Weaver e-cology 9.0 ofsLogin.jsp Arbitrary User Login Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver e-cology provides an integrated mobile office cloud platform, integrating work reporting, project tasks, CRM, knowledge sharing, approval process, data collaboration and other applications in one. Before the version of Weaver e-cology 9.0 10.57.2, there existed any user login vulnerability, which was caused by the third-party login key hard-coded in the background, and the attacker could use the key to calculate specific parameter values, so as to forge any user and log in to Weaver e-cology.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.