CVE-2022-50993
Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malic...
Affects 0 products across 4 vendors.
Application allows file uploads without validating type, enabling upload of executable code or web shells.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Weaver (Fanwei) E-office versions prior to 10.0_20221201 are vulnerable to an unauthenticated arbitrary file upload vulnerability, allowing attackers to upload and execute malicious files.
BSID: BS-2026-GLOBAL-341287-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-50993?
What is the CVSS score for CVE-2022-50993?
Is CVE-2022-50993 actively exploited?
How do I remediate CVE-2022-50993?
What systems are affected by CVE-2022-50993?
| CVE ID | CVE-2022-50993 |
|---|---|
| BSID | BS-2026-GLOBAL-341287-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-04-30 |
| Last Modified | 2026-04-30 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC).
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the OfficeServer.php endpoint, where attackers can send multipart POST requests with arbitrary filenames and disguised content types to upload malicious files, such as PHP webshells, to the Document directory. These webshells can then be executed via HTTP GET requests.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| E-Office | — | — |
| Files | — | — |
| Foundation | — | — |
| Weaver | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | f6a17dc2f86fa6fd4630c53174f65d6bd413dc57d2330f150a2b41e31a9a5c8f42edf2582a248ac1117951f30a48fbe0115666b5c370c1b1c692227d379fddc8 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →