github.comexploit
https://github.com/RCEraser/cve/blob/main/Weaver.md CVE-2023-2523
HIGH
Weaver E-Office unrestricted upload
Record summary
CVE-2023-2523 has a selected CVSS score of 7.3 (high); EIP currently links 2 repository PoCs.
Description
A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228014 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 13, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 2
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
E-OfficeBrowse Weaver / E-Office | CVE List | 9.5 | affected |
e-officeBrowse e-office / e-office | VulnCheck | Version data not supplied | |
Proofs of concept
2Repository PoCs
GitHubAny3ite/CVE-2023-2523Repository PoCby Any3iteStars: 1Not analyzed2 files
GitHubwerwolfz/cve-2023-2523-and-cve-2023-2648Repository PoCby werwolfzStars: 0Not analyzed3 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2523 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.228014 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.228014