A remote code execution (RCE) vulnerability in the...
Critical severity
Unreviewed
Published
Nov 19, 2024
to the GitHub Advisory Database
•
Updated Jun 5, 2025
Description
Published by the National Vulnerability Database
Nov 19, 2024
Published to the GitHub Advisory Database
Nov 19, 2024
Last updated
Jun 5, 2025
A remote code execution (RCE) vulnerability in the component /inventory/doCptimpoptInventory of Weaver Ecology v9.* allows attackers to execute arbitrary code via injecting a crafted payload into the name of an uploaded file.
References