PT-2024-32980 · Unknown · Weaver E-Cology

·

CVE-2024-48070

·

Published

2024-11-19

·

Updated

2025-06-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weaver E-cology versions 9.x
Description The issue allows attackers to construct special requests to insert remote malicious code and trigger malicious code execution, potentially gaining control of server privileges. It is related to a SQL injection vulnerability.
Recommendations For versions 9.x, update to a version that includes a fix for the SQL injection vulnerability to prevent malicious code execution and potential privilege escalation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48070

Affected Products

Weaver E-Cology