PT-2026-36126 · Fanwei · Weaver E-Office

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2022-50993

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weaver (Fanwei) E-office versions prior to 10.0 20221201
Description An unauthenticated arbitrary file upload issue exists in the 'OfficeServer.php' endpoint. Remote attackers can upload malicious files, such as PHP webshells, to the Document directory by sending multipart POST requests with arbitrary filenames and disguised content types. These files can then be executed via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50993

Affected Products

Weaver E-Office