Unauthenticated Arbitrary File Upload in Weaver E-office by Fanwei
CVE-2022-50993
Key Information:
- Vendor
Weaver Network Co., Ltd.
- Status
- Vendor
- CVE Published:
- 30 April 2026
Badges
What is CVE-2022-50993?
Weaver E-office versions before 10.0_20221201 are susceptible to an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint. This flaw enables remote attackers to upload malicious files by leveraging multipart POST requests with arbitrary filenames and misleading content types. Attackers are capable of placing PHP webshells within the Document directory, facilitating remote code execution as the web server user. The first exploitation instances were noted by the Shadowserver Foundation on October 10, 2022.
Affected Version(s)
E-office 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
