Skip to content
Multiple SQL Injection Vulnerabilities Discovered in Chanjet and Weaver Applications

Multiple SQL Injection Vulnerabilities Discovered in Chanjet and Weaver Applications

First seen 19 Sep 2026, 06:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 07:22 UTC
  • Chanjet CRM and Weaver E-Cology have critical SQL injection vulnerabilities.
  • Both vulnerabilities allow unauthorized SQL command execution via web interfaces.
  • No active exploitation has been confirmed, but organizations should patch immediately.

Two SQL injection vulnerabilities have been identified in Chanjet CRM and Weaver E-Cology applications. The Chanjet CRM vulnerability, found in the 'get-usedspace.php' script, allows attackers to manipulate SQL queries via GET requests. Similarly, the Weaver E-Cology vulnerability exists in the 'syncuserinfo.jsp' page, enabling unauthorized SQL command execution. Both vulnerabilities are categorized under CWE-89, indicating improper neutralization of special elements in SQL commands. The scope of impact includes potential data breaches for organizations using these applications. No specific CVEs or active exploitation reports were mentioned in the articles. Organizations are advised to prioritize patching these vulnerabilities to mitigate risks. The current status of both vulnerabilities is disclosed but without confirmed exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-19
Chanjet CRM SQL Injection disclosed
A vulnerability in 'get-usedspace.php' allows SQL injection via GET requests, affecting Chanjet CRM users.
VulnCheck
2026-09-19
Weaver E-Cology SQL Injection disclosed
A vulnerability in 'syncuserinfo.jsp' enables SQL injection, impacting Weaver E-Cology applications.
VulnCheck

More articles in this cluster (2)