RULE(RULE ID:337837)

Rule General Information
Release Date: 2024-03-06
Rule Name: Weaver E-office login.wsdl.php SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-office is a standard collaborative mobile office platform under Weaver.There is a SQL injection vulnerability in Weaver E-office v9.0 version 141103, and attackers can use this vulnerability to obtain any user account information, password, mobile phone number, etc. in the system.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.