Record summary

CVE-2023-2523 has a selected CVSS score of 7.3 (high); EIP currently links 2 repository PoCs.

Description

A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228014 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 13, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List9.5affected
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubAny3ite/CVE-2023-2523Repository PoCby Any3iteStars: 1Not analyzed2 files

3.5 KiB

GitHub

PoC details
GitHubwerwolfz/cve-2023-2523-and-cve-2023-2648Repository PoCby werwolfzStars: 0Not analyzed3 files

8.5 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

4