← back
CVE-2023-2648mediumobserved exploitationCWE-434

Weaver E-Office uploadify.php unrestricted upload

75Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 6.3epss 28%
from disclosure to weapon530 days
Published on NVDMay 11
1st PoC+530d
VulnCheck+301d
exploitation probability
28%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
Weaver · E-Office
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.