RULE(RULE ID:339009)

Rule General Information
Release Date: 2025-06-04
Rule Name: Weaver E-Cology getFileViewUrl SSRF Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-cology is a high-end collaborative office system designed for large enterprises and groups. It provides comprehensive functions such as process management, knowledge management, and project management. It supports multiple organizations, departments, and users, helping enterprises achieve efficient collaboration and digital transformation. There is a Server-Side Request Forgery (SSRF) vulnerability in the getFileViewUrl of Weaver E-cology. Attackers can exploit this vulnerability to induce the server to initiate malicious download requests, thereby bypassing access restrictions, stealing sensitive data, attacking internal network services, or triggering other vulnerabilities to further expand the scope of the attack.
Impact: SSRF is a security vulnerability constructed by an attacker to form a request initiated by a server. By exploiting this vulnerability, an attacker can bypass access restrictions such as firewalls, thereby using an infected or vulnerable server as a proxy for port scanning and even accessing internal system data.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.