Sploitus

CVE-2023-2648

2 known exploits for CVE-2023-2648

A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products
Weaver E-Office, Uploadify
Weaver E-office
= 9.5
CVSS 3.1
9.8 CRITICAL
EPSS
28.5% (98th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2023-05-11
CVE-2023-2648 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2023-2648

Proof-of-concept code and exploit modules indexed by Sploitus