---
id: CVE-2019-25776
title: >-
  Weaver E-cology contains an unauthenticated SQL injection vulnerability that
  allows remote attackers to execute arbitrary SQL queries by submitting
  malicious input through the userIdentifiers GET parameter in the mobile plugin
  endpoint
summary: >-
  Weaver E-cology contains an unauthenticated SQL injection vulnerability that
  allows remote attackers to execute arbitrary SQL queries by submitting
  malicious input through the userIdentifiers GET parameter in the mobile plugin
  endpoint. …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
vendor: 'Weaver Network Co., Ltd.'
product: E-cology
affected:
  - E-cology
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25776'
references:
  - url: 'https://cn-sec.com/archives/135359.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/chaitin/xray/blob/master/pocs/ecology-syncuserinfo-sqli.yml
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/weaver-e-cology-sql-injection-via-syncuserinfo-jsp
    label: disclosure@vulncheck.com
  - url: 'https://www.weaver.com.cn/cs/ecology_full_log_en.html'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00361
epssPercentile: 0.29929
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T15:20:29.978539Z'
ingestedAt: '2026-09-18T19:49:30.579Z'
---

## Overview

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. Attackers can bypass space-based filter controls by wrapping SQL keywords in parentheses to perform UNION-based injection and extract sensitive data including administrator credential hashes from the database. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-07-28.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
