NVD HIGH: CVE-2022-50997 — Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in t...
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data
CVE-2022-50997