Rule Name:Weaver e-cology9 Arbitrary User Login Vulnerability
Severity:critical
CVE ID:
Descripiton:
Weaver e-cology is a set of medium and large-scale efficient collaborative office environment. In some versions of Weaver e-Cology9, the third-party login key is hard-coded, and attackers can use the key to calculate specific parameter values, thereby forging arbitrary users to take over Weaver e-Cology. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None