CVE-2019-10272: Weaver E-Cology

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isintervenor parameter, as demonstrated by the %0aSet-cookie: substring.

Affected products

  • Weaver E-Cology: version 9.0 only

Published 2019-04-30. Last modified 2026-06-17.