{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/e-cology-9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2022-4995"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["E-cology 9.0"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","file-upload","webserver"],"_cs_type":"threat","_cs_vendors":["Weaver"],"content_html":"\u003cp\u003eWeaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a critical arbitrary file upload vulnerability (CVE-2022-4995) that enables remote, unauthenticated attackers to gain remote code execution (RCE). The vulnerability exists within the /workrelate/plan/util/uploaderOperate.jsp endpoint, which fails to properly validate incoming file uploads. By sending a crafted multipart/form-data POST request containing arbitrary secId and plandetailid parameters, an attacker can upload malicious JSP files to the web server. Once the file is written to the application's accessible web root, the attacker can execute arbitrary commands under the context of the application server process. This vulnerability has been subject to active exploitation in the wild since at least October 14, 2023.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Weaver E-cology 9.0 instances.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a multipart/form-data HTTP POST request targeting /workrelate/plan/util/uploaderOperate.jsp.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious JSP webshell into the body of the multipart request.\u003c/li\u003e\n\u003cli\u003eAttacker includes arbitrary values in the secId and plandetailid fields to bypass application-level checks.\u003c/li\u003e\n\u003cli\u003eThe vulnerable server accepts the request and writes the JSP file to an accessible directory.\u003c/li\u003e\n\u003cli\u003eAttacker sends a GET request to the newly uploaded JSP file path to trigger code execution.\u003c/li\u003e\n\u003cli\u003eThe application server process executes the embedded commands, granting the attacker RCE.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2022-4995 results in full remote code execution, allowing attackers to compromise the application server. This can lead to total system takeover, data exfiltration, and potential lateral movement within the affected organization. Given the nature of the application, these servers often house sensitive corporate documents and internal project planning data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Weaver E-cology 9.0 instances to version 10.52 or later to mitigate CVE-2022-4995.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for exploitation attempts targeting the identified JSP upload endpoint.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) to restrict access to /workrelate/plan/util/uploaderOperate.jsp to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eAudit the web root directory for suspicious JSP files created after October 2023.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-07T15:33:27Z","date_published":"2026-08-07T15:33:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-weaver-e-cology-rce/","summary":"Weaver E-cology 9.0 versions prior to 10.52 are vulnerable to unauthenticated arbitrary file upload via the /workrelate/plan/util/uploaderOperate.jsp endpoint, allowing remote code execution.","title":"Unauthenticated Remote Code Execution in Weaver E-cology 9.0","url":"https://feed.craftedsignal.io/briefs/2026-08-weaver-e-cology-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - E-Cology 9.0","version":"https://jsonfeed.org/version/1.1"}