PT-2026-69048 · Fanwei · E-Cology 9.0

CVE-2022-4995

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weaver (Fanwei) E-cology 9.0 versions prior to 10.52
Description A file upload issue allows a remote, unauthenticated attacker to upload arbitrary files, such as JSP webshells. This is achieved by submitting a multipart/form-data POST request to the endpoint '/workrelate/plan/util/uploaderOperate.jsp' using arbitrary values for the secId and plandetailid variables. Successful exploitation enables remote code execution with the privileges of the application server process. Evidence of exploitation was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).
Recommendations Update Weaver (Fanwei) E-cology 9.0 to version 10.52 or later. Restrict access to the endpoint '/workrelate/plan/util/uploaderOperate.jsp' to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4995

Affected Products

E-Cology 9.0