← volver
CVE-2023-2648mediumexplotación observadaCWE-434

Weaver E-Office uploadify.php unrestricted upload

75Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 6.3epss 28%
de la publicación al arma530 días
Publicada en NVD11 may
1ª PoC+530d
VulnCheck+301d
probabilidad de explotación
28%top 2% de las CVE
explotación observada
VulnCheck
1 exploit(s) público(s)
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
Weaver · E-Office
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.