CVE-2023-2766
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 91.82%
- CWE
- CWE-552
- Published
- 2023-05-17
- Last modified
- 2026-03-13
Affected products
- Weaver OA
Weakness type
Related vulnerabilities
- CVE-2023-50164 — Apache Struts: File upload component had a directory traversal vulnerability
- CVE-2024-6911 — Unauthenticated Local File Inclusion
- CVE-2024-6209 — unauthorized file access
- CVE-2025-34110 — ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
- CVE-2009-10005 — ContentKeeper Web Appliance < 125.10 Arbitrary File Access via mimencode
- CVE-2023-48710 — iTop limit pages/exec.php script to PHP files
- CVE-2020-37082 — webERP 4.15.1 - Unauthenticated Backup File Access