CVE-2022-50992: Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet

Published Apr 30, 2026
·
Updated

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).

Affected Software

1 affected component
weaver Weaver E-cology<10.52

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Weaver (Fanwei) E-cology 9.5 to a version that resolves this vulnerability.

    Fixed in 10.52
  2. Configuration

    Disable the XML-RPC endpoint or restrict it so that unauthenticated remote attackers cannot access XmlRpcServlet methods (WorkflowService.getAttachment and WorkflowService.LoadTemplateProp).

    Weaver (Fanwei) E-cology XML-RPC endpoint (XmlRpcServlet / XmlRpcServlet interface) XML-RPC exposure / availability = Disable or restrict unauthenticated access
  3. Compensating control

    Restrict network access to the server hosting the Weaver E-cology XML-RPC endpoint (XmlRpcServlet) to trusted IPs only, to reduce exposure to unauthenticated arbitrary file read attempts.

Event History

Apr 30, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-50992?

CVE-2022-50992 is classified as a high severity vulnerability due to its ability to allow unauthenticated remote attackers to read arbitrary files.

2

How do I fix CVE-2022-50992?

To fix CVE-2022-50992, upgrade Weaver E-cology to version 10.52 or later to mitigate the arbitrary file read vulnerability.

3

What versions of Weaver E-cology are affected by CVE-2022-50992?

Weaver E-cology versions prior to 10.52 are affected by CVE-2022-50992.

4

Can CVE-2022-50992 be exploited remotely?

Yes, CVE-2022-50992 can be exploited remotely as it does not require authentication.

5

What type of vulnerability is CVE-2022-50992?

CVE-2022-50992 is an arbitrary file read vulnerability found in the XmlRpcServlet interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203