CVE detail
CVE-2022-50997
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software version 10.53 or 10.54. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.weaver.com.cn/cs/securityDownload.html#www.weaver.com.cn
No excerpt available.
Patchwww.weaver.com.cnAug 11, 2026, 6:17 PM - https://www.weaver.com.cn/cs/ecology_full_log_en.htmlwww.weaver.com.cn
No excerpt available.
Patchwww.weaver.com.cnAug 11, 2026, 6:17 PM - https://www.vulncheck.com/advisories/weaver-e-cology-sql-injection-via-hrmcareerapplyperview-jspwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comAug 11, 2026, 6:17 PM No excerpt available.
referencepeiqi.wgpsec.orgAug 11, 2026, 6:17 PM- https://cn-sec.com/archives/1211578.htmlcn-sec.com
No excerpt available.
referencecn-sec.comAug 11, 2026, 6:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73332CVSS 9.2 · Critical
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by sub…
- CVE-2026-73331CVSS 7.1 · High
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value…
- CVE-2026-72807CVSS 8.8 · High
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL us…
- CVE-2026-67579CVSS 7.5 · High
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resu…
- CVE-2026-17111CVSS 7.6 · High
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or…
- CVE-2026-73300CVSS 9.6 · Critical
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multi…