Impact
Weaver (Fanwei) E‑cology 9.0 has a file‑upload flaw that permits an unauthenticated attacker to post any multipart/form‑data payload to uploaderOperate.jsp and, by naming the secId and plandetailid fields arbitrarily, push an arbitrary file into the web application. When the payload contains a JSP webshell, the server executes it with the same privileges as the application process, giving the attacker full control and the ability to read, modify, or delete data. The weakness is a classic unrestricted upload (CWE-434).
Affected Systems
Weaver Network Co., Ltd. E‑cology 9.0 versions prior to 10.52 are affected. No specific sub‑product names beyond the main E‑cology 9.0 line are listed.
Risk and Exploitability
The CVSS score of 9.3 marks this vulnerability as critical. The attack vector is remote, over HTTP, and requires no authentication or local access, meaning an adversary can attempt it from the public internet. EPSS is not available, so there is no explicit probability estimate, but the lack of a KEV listing does not imply it is harmless. Because the vulnerability is triggered by a simple POST request, exploitation can be automated and could lead to immediate compromise of the entire application.
OpenCVE Enrichment