An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:weaver:e-cology:9.0:*:*:*:*:*:*:*

Thu, 21 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Weaver
Weaver e-cology
Weaknesses CWE-94
CPEs cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:*
Vendors & Products Weaver
Weaver e-cology
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 15:00:00 +0000

Type Values Removed Values Added
Description Weaver Ecology v9* was discovered to contain a SQL injection vulnerability. An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges

Tue, 19 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
Description Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-21T16:36:00.273Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48070

cve-icon Vulnrichment

Updated: 2024-11-21T16:35:39.672Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-19T18:15:21.353

Modified: 2025-06-05T13:55:09.977

Link: CVE-2024-48070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.