VYPR
Medium severity5.5NVD Advisory· Published Jul 20, 2023· Updated Jun 17, 2026

CVE-2023-3793

CVE-2023-3793

Description

A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownloadForOutDoc.class of the component HTTP POST Request Handler. The manipulation of the argument fileid with the input 1+WAITFOR+DELAY leads to sql injection. Upgrading to version 10.58.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-235061 was assigned to this vulnerability.

Affected products

3
  • Weaver/Ecology2 versions
    cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:*range: <10.58.0
    • (no CPE)range: n/a
  • Range: before 10.58.0

Patches

Vulnerability mechanics

References

2
  • vuldb.comnvdPermissions RequiredThird Party Advisory
  • vuldb.comnvdPermissions RequiredThird Party Advisory

News mentions

0

No linked articles in our index yet.