E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to permanently deny service.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Weaver
Weaver e-cology
CPEs cpe:2.3:a:weaver:e-cology:9.0:*:*:*:*:*:*:*
Vendors & Products Weaver
Weaver e-cology

Thu, 21 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 15:30:00 +0000

Type Values Removed Values Added
Description An issue in the component /importmould/deletefolder of Weaver Ecology v9.* allows authenticated attackers to execute a directory traversal and arbitrarily delete files. E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to permanently deny service.

Tue, 19 Nov 2024 17:00:00 +0000

Type Values Removed Values Added
Description An issue in the component /importmould/deletefolder of Weaver Ecology v9.* allows authenticated attackers to execute a directory traversal and arbitrarily delete files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-21T16:38:59.609Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48071

cve-icon Vulnrichment

Updated: 2024-11-21T16:38:47.002Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-19T17:15:09.267

Modified: 2025-09-24T19:08:16.453

Link: CVE-2024-48071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.