RULE(RULE ID:338275)

Rule General Information
Release Date: 2024-07-30
Rule Name: Weaver E-cology WorkPlanService SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-cology is an enterprise-level collaborative office platform, which supports information sharing, communication, collaboration and knowledge management by integrating various office applications and workflow, to improve work efficiency and organizational management ability. The WorkPlanService interface of Weaver E-cology has a SQL injection vulnerability, through which attackers can inject malicious SQL statements, which may cause remote code execution. Impact version: E-cology8 is less than v10.65, E-cology9 is less than v10.65.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.