www.vulncheck.com Multiple SQL Injection Vulnerabilities Discovered in Chanjet and Weaver Applications
Article Content
- •Chanjet CRM and Weaver E-Cology have critical SQL injection vulnerabilities.
- •Both vulnerabilities allow unauthorized SQL command execution via web interfaces.
- •No active exploitation has been confirmed, but organizations should patch immediately.
Two SQL injection vulnerabilities have been identified in Chanjet CRM and Weaver E-Cology applications. The Chanjet CRM vulnerability, found in the 'get-usedspace.php' script, allows attackers to manipulate SQL queries via GET requests. Similarly, the Weaver E-Cology vulnerability exists in the 'syncuserinfo.jsp' page, enabling unauthorized SQL command execution. Both vulnerabilities are categorized under CWE-89, indicating improper neutralization of special elements in SQL commands. The scope of impact includes potential data breaches for organizations using these applications. No specific CVEs or active exploitation reports were mentioned in the articles. Organizations are advised to prioritize patching these vulnerabilities to mitigate risks. The current status of both vulnerabilities is disclosed but without confirmed exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…