Weaver E-cology9 SQL Injection Scanner

Detects 'SQL Injection' vulnerability in Weaver E-cology9.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

18 days 4 hours

Scan only one

Domain, Subdomain, IPv4

Toolbox

Weaver E-cology9 is a comprehensive office automation software utilized predominantly in enterprise environments for streamlining business processes. It is widely adopted by companies to support functions such as document management, workflow management, and collaboration tools. The software serves the needs of various stakeholders, including employees, managers, and IT administrators, facilitating day-to-day operations across departments. It's designed as a scalable solution to accommodate varying business sizes while ensuring integration with existing infrastructure. Weaver E-cology9 provides a centralized platform for managing multiple facets of business operations, enhancing productivity and efficiency. Its versatile nature makes it a popular choice in both small and large organizations seeking to digitize and automate workflows.

The SQL Injection vulnerability found in Weaver E-cology9 allows an attacker to inject malicious SQL queries into the application's database query engine. Exploiting this vulnerability enables attackers to manipulate SQL queries, leading to unauthorized data access or data manipulation. This security flaw is typically located in a specific API endpoint, `/api/doc/out/more/list`, which does not adequately sanitize input parameters. As a result, crafted requests can initiate backend SQL execution, posing serious risks to data integrity and confidentiality. Attackers can exploit the vulnerability to bypass authentication, retrieve sensitive information, or execute additional database commands. It increases the susceptibility of the system to broader attacks and unauthorized data disclosure.

The vulnerable endpoint is `/api/doc/out/more/list`, where certain parameters such as `isNew`, `elementmore`, and date-related fields are susceptible to injection. The SQL Injection occurs when these parameters are manipulated to include SQL commands, taking advantage of the lack of proper input validation. For instance, using crafted strings like `a'OR-1/*a` can trigger the execution of unintended SQL commands. After successfully exploiting this endpoint, a session key is generated, which can be further misused to extract data via another endpoint, `/api/ec/dev/table/counts`. This chained exploitation allows attackers to execute queries and confirm their success through the retrieval of query results.

If exploited, this SQL Injection vulnerability can lead to severe security implications, including unauthorized access to sensitive database information. Attackers gaining access to critical business data can compromise confidentiality, integrity, and availability of the information. It may lead to data breaches, financial loss, and reputational damage to the organization. Moreover, attackers could manipulate or corrupt data, impacting operational processes and decisions. In extreme cases, these vulnerabilities might be leveraged to gain further access into the network, putting additional assets at risk.

REFERENCES

Get started to protecting your digital assets