'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Weaver OA e-cology Action.jsp MobileAppUploadAction Aribitrary File Upload Vulnerability
Severity:high
CVE ID:
| Descripiton:
|
Weaver e-cology is an Office Automation (OA) software developed by Weaver Software, a Chinese company. The software aims to provide an integrated solution for internal office processes within enterprises, enhancing office efficiency and information management.Weaver e-cology has a vulnerability that allows arbitrary file upload, enabling malicious attackers to upload files to the server through the uploaderOperate method and gain control over it. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.