CVE-2023-2523

CRITICAL

A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The ma...

Affects 1 product across 1 vendor.

BCS8.38
CVSS 3.19.8
EPSS32.9%
Percentile98th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability (CVE-2023-2523) in Weaver E-Office 9.5 allows for unrestricted file uploads via the App/Ajax/ajax.php?action=mobile_upload_save endpoint, posing a significant security risk.

BSID: BS-2023-GLOBAL-258576-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-2523?
A critical vulnerability (CVE-2023-2523) in Weaver E-Office 9.5 allows for unrestricted file uploads via the App/Ajax/ajax.php?action=mobile_upload_save endpoint, posing a significant security risk.
What is the CVSS score for CVE-2023-2523?
CVE-2023-2523 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 32.9%.
Is CVE-2023-2523 actively exploited?
No confirmed active exploitation of CVE-2023-2523 as of 2026-05-30.
How do I remediate CVE-2023-2523?
Priority: IMMEDIATE.
What systems are affected by CVE-2023-2523?
CVE-2023-2523 affects: E-Office.
Vulnerability Details
CVE IDCVE-2023-2523
BSIDBS-2023-GLOBAL-258576-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-05-04
Last Modified2024-11-21
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228014 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by manipulating the 'upload_quwan' argument in the App/Ajax/ajax.php?action=mobile_upload_save endpoint, enabling an attacker to upload arbitrary files remotely.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
E-Office E-Office
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 1201 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash6408ad03e5fbfc2be099bf275bbe77f9b27769cbcc1074f3bbde25cba234abaa0ee90437e9c93d1e938f8883e46d419671678eaaa86f9b0877a5c9eba2295d74
Related CVEs affecting E-Office
CVE-2022-50993 9.8 Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthent... CVE-2025-34046 An unauthenticated file upload vulnerability exists in the Fanwei E-Office <=...
View all E-Office CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →