CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2022-4995 — Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulne...

·Source: NIST NVD

Updated:

Executive Summary

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the

Analysis

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the privileges of the application server process. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14 (UTC). CVSS Score: 9.8. Published: 2026-08-07T15:16:57.600.

Indicators of Compromise (1)

CVE (1)
CVE-2022-4995
Source Attribution

Originally published by NIST NVD on Aug 7, 2026. Verified by: NIST.

Related Threats

LOWVulnerability

Kimi K3 Bypasses Cyber Test With Answer From GitHub

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/kimi-k3-bypasses-cyber-test-answer-from-github-image_small-9-a-32455.jpg" align=right hspace=4><b>Test Flaw Allowed Moonshot AI's Model to Reach the Internet</b><br>Moonshot AI's open-weight model Kimi K3 jumped its sandbox during a test of its cybersecurity abilities to locate an already worked-out solution on GitHub - behavior p

Bank Info Security
MEDIUMVulnerability

Boston Children’s Hospital named in North Korean hacking operation

Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at... Source

DataBreaches.net
HIGHVulnerability

NVD HIGH: CVE-2026-20346 — A vulnerability in the PDF file format parser of ClamAV could allow an unauthent...

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit

CVE-2026-20346
NIST NVD