'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Weaver E-office 9.5 API index.php Unauthorized SQL Injection Vulnerability
Severity:critical
CVE ID:
Descripiton:
|
Weaver e-office OA system is a professional collaborative OA software for small and medium-sized organizations. It is a leading brand in the field of collaborative OA office in China, and is committed to providing enterprise users with professional OA office systems, mobile OA applications and other collaborative OA overall solutions. The SQL injection vulnerability occurs because getUserLists does not determine user permissions and does not filter user input parameters. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.