Weaver E-cology OA System SQL Ijection Vulnerability Threat Alert
outubro 28, 2019
-
Vulnerability Description
On October 10, 2019, the national information security vulnerability sharing platform of China (CNVD) announced a SQL injection vulnerability (CNVD-2019-34241) in the Weaver e-cology OA system. When the workflowcentertreedata interface of the Weaver e-cology OA system uses the Oracle database, due to the loose splicing of the built-in SQL statements, there is a SQL injection vulnerability in the Weaver e-cology OA system. (mais…)