RULE(RULE ID:339008)

Rule General Information
Release Date: 2025-06-04
Rule Name: Weaver E-Cology HrmService SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-cology is a high-end collaborative office system designed for large enterprises and groups. It provides comprehensive functions such as process management, knowledge management, and project management. It supports multiple organizations, departments, and users, helping enterprises achieve efficient collaboration and digital transformation. There is an SQL injection vulnerability in the HrmService interface of Weaver E-cology. Attackers can exploit this vulnerability to steal sensitive information, tamper with database data, control the database server, and even further intrude into the entire system.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.