Junglewise Threat Intelligence

CVE-2022-50997: Weaver E-cology SQL injection in HrmCareerApplyPerView.jsp

CVE-2022-50997 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: Weaver E-cology. Vendors: Weaver.

Executive brief

Weaver E-cology is a widely deployed enterprise resource planning and office automation system used by organizations to manage human resources, workflows, and business processes. An unauthenticated SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint allows attackers to extract sensitive data directly from the backend database—including employee records, financial information, and other confidential business data—by sending a single malicious web request.

Technical details

The vulnerability is a SQL injection flaw in the HrmCareerApplyPerView.jsp endpoint, where the unsanitized id GET parameter is passed directly into SQL queries. An unauthenticated remote attacker can inject UNION-based SQL payloads through this parameter to query the Microsoft SQL Server backend and retrieve arbitrary data. No authentication is required; attackers can exploit this by crafting a single HTTP GET request with malicious SQL syntax embedded in the id parameter. The vulnerability allows confidentiality breach through unauthorized database access. Patches are available in software versions 10.53 or later.

Affected products

  • Weaver E-cology 8.0, 9.0

Timeline

  • 2022: disclosed: Vulnerability reported in 2022 HVV security assessment
  • 2023-10-18: exploited: Exploitation evidence first observed by Shadowserver Foundation

References

Related threats