Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet

What is CVE-2022-50993?

CVE-2022-50993 is a vulnerability classified as Unrestricted Upload of File with Dangerous Type, affecting E-office (affected versions: < 10.0_20221201). This vulnerability is rated Critical, with a CVSS score of 9.3. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC).

Affected products and scope

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical details

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Exploitability

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Business impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Remediation

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Detection

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Sources (5)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard