A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-01-24T21:14:05.440Z
Reserved: 2023-05-11T05:32:57.638Z
Link: CVE-2023-2648
Updated: 2024-08-02T06:26:09.905Z
Status : Modified
Published: 2023-05-11T08:15:08.773
Modified: 2024-11-21T07:59:00.100
Link: CVE-2023-2648
No data.
OpenCVE Enrichment
No data.