VYPR

E-Office

by Weaver

CVEs (8)

  • CVE-2022-50993CriApr 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and…

  • CVE-2023-34798CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-2523HigMay 4, 2023
    risk 0.50cvss 7.3epss 0.33

    A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack…

  • CVE-2023-2648MedMay 11, 2023
    risk 0.43cvss 6.3epss 0.28

    A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2023-2647MedMay 11, 2023
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroot/inc/utility_all.php of the component File Upload Handler. The manipulation leads to command injection. The attack may be…

  • CVE-2023-2766MedMay 17, 2023
    risk 0.39cvss 5.3epss 0.54

    A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated…

  • CVE-2024-3227MedApr 3, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument image_type leads to path…

  • CVE-2023-2765MedMay 17, 2023
    risk 0.28cvss 4.3epss 0.02

    A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated…