PT-2026-69048 · Fanwei · E-Cology 9.0
CVE-2022-4995
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52
Description
A file upload issue allows a remote, unauthenticated attacker to upload arbitrary files, such as JSP webshells. This is achieved by submitting a multipart/form-data POST request to the endpoint '/workrelate/plan/util/uploaderOperate.jsp' using arbitrary values for the
secId and plandetailid variables. Successful exploitation enables remote code execution with the privileges of the application server process. Evidence of exploitation was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).Recommendations
Update Weaver (Fanwei) E-cology 9.0 to version 10.52 or later.
Restrict access to the endpoint '/workrelate/plan/util/uploaderOperate.jsp' to minimize the risk of exploitation.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Cology 9.0