CVE-2022-4995
Received Received - Intake

File Upload RCE Vulnerability in Weaver E-cology 9.0

Vulnerability report for CVE-2022-4995, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: VulnCheck

Description

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
weaver e-cology to 10.52 (exc)
weaver e-cology 8.5
weaver e-cology 8.2
weaver e-cology 10.79
weaver e-cology 10.56
weaver e-cology 10.78
weaver e-cology 10.11
weaver e-cology 6.51
weaver e-mobile *
weaver e-bridge *
weaver esearch *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2022-4995 is a critical file upload vulnerability in Weaver E-cology 9.0 versions prior to 10.52. It allows remote unauthenticated attackers to upload arbitrary files, including malicious JSP webshells, via a crafted multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp. Successful exploitation enables remote code execution with the privileges of the application server process.

Detection Guidance

Check for unusual file uploads to /workrelate/plan/util/uploaderOperate.jsp or interactions with /OfficeServer. Monitor for POST requests with multipart/form-data containing JSP files. Look for unexpected files in web-accessible directories like hello.jsp.

Impact Analysis

This vulnerability allows attackers to upload and execute arbitrary files on the server, leading to full system compromise. Attackers could gain control of the application server, access sensitive data, or perform further attacks within the network. Exploitation evidence was observed in the wild as early as October 2023.

Compliance Impact

This vulnerability allows remote code execution through arbitrary file uploads, which could lead to unauthorized access to sensitive data. This may violate GDPR's data protection requirements (e.g., Article 32 on security of processing) and HIPAA's safeguards for protected health information (e.g., Security Rule). Unauthorized access risks data breaches, potentially resulting in non-compliance with these regulations.

Mitigation Strategies

Apply the latest security patches for Weaver E-cology 9.0 or upgrade to version 10.52 or later. Block access to /workrelate/plan/util/uploaderOperate.jsp and /OfficeServer. Implement strict file upload validation and restrict web root write permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2022-4995. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart