CVE-2023-34798

An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:weaver:e-office:*:*:*:*:*:*:*:*

History

01 Aug 2023, 01:38

Type Values Removed Values Added
CPE cpe:2.3:a:weaver:e-office:*:*:*:*:*:*:*:*
CWE CWE-434
First Time Weaver
Weaver e-office
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://gist.github.com/Zhu013/e5e6e03613704a2a4107cc6456f1e8e2 - (MISC) https://gist.github.com/Zhu013/e5e6e03613704a2a4107cc6456f1e8e2 - Third Party Advisory

25 Jul 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-25 20:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-34798

Mitre link : CVE-2023-34798

CVE.ORG link : CVE-2023-34798


JSON object : View

Products Affected

weaver

  • e-office
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type