PatchSiren

Weaver Network Co., Ltd. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Weaver Network Co., Ltd. CVE published 2026-08-11

CVE-2022-50997

CVE-2022-50997 debrief based on the supplied source corpus. Weaver (Fanwei) E-cology 8.0 and 9.0 contain a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint. This vulnerability allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. The vulnerability is potentially remediated in software version 10.53 or 10.54. E [truncated]

HIGH Weaver Network Co., Ltd. CVE published 2026-08-11

CVE-2016-20097

CVE-2016-20097 Weaver (Fanwei) E-cology 8.0 SQL injection vulnerability allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter. This enables attackers to control the markPath value, causing the servlet to read and stream back arbitrary files accessible to the application server process, including sensitive configuration files conta [truncated]