Impact
Weaver's E‑cology 8.0 and 9.0 contain an unauthenticated SQL injection in HrmCareerApplyPerView.jsp. By supplying a crafted id GET parameter, attackers can terminate the original query and append a UNION‑based payload that reads arbitrary tables from the Microsoft SQL Server backend. This flaw, classified as CWE‑89, enables the extraction of sensitive data such as personal information, credentials, or configuration details without needing valid credentials.
Affected Systems
The vulnerable component is the HrmCareerApplyPerView.jsp endpoint hosted by Weaver Network Co., Ltd. The exposed products are E‑cology 8.0 and E‑cology 9.0. The vendor notes that versions 10.53 or 10.54 contain a remediation. No specific patch version is listed for the 8.0/9.0 line, indicating that users must upgrade to the latest 10.x release or apply the vendor’s fix.
Risk and Exploitability
The vulnerability scores a high CVSS of 8.7, indicating a major risk, but its EPSS score is below 1 %, suggesting a low exploitation probability at present. It is not in the CISA KEV catalogue. Attackers could exploit the flaw remotely from the web interface without authentication by sending a single crafted GET request. While exploitation evidence surfaced in October 2023, the low EPSS does not negate the need for timely remediation.
OpenCVE Enrichment