RULE(RULE ID:338990)

Rule General Information
Release Date: 2025-06-04
Rule Name: Weaver E-Weaver getSqlData SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-Weaver is a high-end collaborative office platform designed for large organizations. It provides comprehensive functions such as office automation, process management, and knowledge management. It supports a large number of users and complex business processes, helping enterprises improve operational efficiency and collaborative capabilities. There is a SQL injection vulnerability in the getSqlData interface of Weaver E-Weaver. Attackers can exploit this vulnerability to steal sensitive information, tamper with database data, control the database server, and even further intrude into the entire system.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.