Impact
Weaver E‑cology contains an unauthenticated SQL injection flaw in the userIdentifiers GET parameter of the SyncUserInfo.jsp endpoint. Attackers can craft input that uses parentheses to bypass the application’s space‑based filtering and perform UNION‑based injection to execute arbitrary SQL queries. This allows direct exposure of sensitive data, including administrator credential hashes, and potentially other database contents.
Affected Systems
The affected vendor is Weaver Network Co., Ltd. and the product is E‑cology. No specific version information is provided in the advisory.
Risk and Exploitability
The flaw has a CVSS score of 8.7, indicating high severity. An EPSS score is not available and the vulnerability is not listed in CISA KEV. Because the injection is unauthenticated and targets a mobile plugin endpoint that is reachable over the network, attackers can easily send HTTP GET requests to exploit it. The vulnerability was actively observed in 2022, confirming that it can be leveraged in the wild.
OpenCVE Enrichment