CVE-2022-4995: Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4995?
CVE-2022-4995 has a severity rating of critical, with a score of 9.8.
How does CVE-2022-4995 work?
CVE-2022-4995 works by allowing unauthenticated attackers to upload arbitrary files, including JSP webshells, through a vulnerable file upload feature.
How do I fix CVE-2022-4995?
To mitigate CVE-2022-4995, you should upgrade Weaver E-cology to version 10.52 or later.
What type of attack does CVE-2022-4995 enable?
CVE-2022-4995 enables remote code execution (RCE) attacks via malicious file uploads.
What is the effect of exploiting CVE-2022-4995?
Exploiting CVE-2022-4995 can lead to unauthorized access and full control of the affected server.