NA

CVE-2023-2523

Published: 04/05/2023 Updated: 14/05/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228014 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

e-office e-office 9.5

Github Repositories

CVE-2023-2523 CVE-2023-2523

2023泛微0A漏洞poc检测工具

2023-Weaver-pocs 2023泛微0A漏洞poc检测工具 支持检测漏洞 泛微 E-Office文件上传漏洞(CVE-2023-2523) 泛微 E-Office文件上传漏洞(CVE-2023-2648) 泛微E-Cology SQL注入漏洞(CVE-2023-15672) 泛微OA E-Cology9未授权SQL注入漏洞(CNVD-2023-12632) 泛微OA e-cology前台接口SQL注入漏洞 泛微 e-cology ofsLogin任意用户登录漏洞 泛微E-

泛微最近的漏洞利用工具(PS:2023)

WeaverExploit_All 泛微最近的漏洞利用工具(PS:2023) 集成了QVD-2023-5012、CVE-2023-2523、CVE-2023-2648、getloginid_ofsLogin 漏洞利用 2023726:新增:WorkflowServiceXml 内存马注入、uploaderOperate文件上传漏洞、DeleteUserRequestInfoByXml 、FileDownloadForOutDocSQL注入、E-Mobile 60 命令执行漏洞检测 2023805:新增泛微E-

cve-2023-2523-and-cve-2023-2648

cve-2023-2523 备注:脚本上传了phpinfo文件 使用方法: 结果自动保存到resulttxt文件 手工POC: POST /E-mobile/App/Ajax/ajaxphp?action=mobile_upload_save HTTP/11 Host: your-ip Content-Length: 352 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: null Content-Type: multipart/form-data; boundary=----WebKitFormBoundarydRVCGWq4Cx3Sq6tt User-Ag

nuclei templates

ntps nuclei templates headless bing-search http-cves 2023 CVE-2023-1389 CVE-2023-2523 CVE-2023-2648 CVE-2023-49442 http-vulnerabilities 安恒 anheng-gateway-rce-cnvd-2023-03898 anheng-mingyu-xmlrpc-sock-ssrf 畅捷通 changjet-tplus-ajaxpro-rce changjet-tplus-downloadproxy-traversal 大华 dahua-passowrd-disclosure dahua-publishing-fileupload dahua-searchJson-sqli dah