Vulnerability Description
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software version 10.53 or 10.54. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://cn-sec.com/archives/1211578.html
- https://peiqi.wgpsec.org/wiki/oa/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEOA%20E-C
- https://www.vulncheck.com/advisories/weaver-e-cology-sql-injection-via-hrmcareer
- https://www.weaver.com.cn/cs/ecology_full_log_en.html
- https://www.weaver.com.cn/cs/securityDownload.html#
FAQ
What is CVE-2022-50997?
CVE-2022-50997 is a vulnerability with a CVSS score of 7.5 (HIGH). Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the ba...
How severe is CVE-2022-50997?
CVE-2022-50997 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50997?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.