'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Weaver E-Cology KtreeUploadAction Arbitrary File Upload Vulnerability
Severity:high
CVE ID:
| Descripiton:
|
Weaver E-Cology is an enterprise level collaborative office platform. It supports information sharing, communication and collaboration, and knowledge management within the enterprise by integrating a variety of office applications and workflow to improve work efficiency and organizational management capabilities. There is a file upload vulnerability in the KtreeUploadAction interface of Weaver E-Cology, through which an attacker can upload webshells to control the web server. There is a certain possibility of false positives in this rule, and it needs to be judged based on the specific content of the message. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.