CVE-2023-2766: Weaver OA jx2_config.ini file access
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2766?
CVE-2023-2766 is classified as a problematic vulnerability affecting Weaver OA 9.5.
How do I fix CVE-2023-2766?
Fixing CVE-2023-2766 requires implementing proper access controls and updating to a patched version of the Weaver OA software.
What systems are affected by CVE-2023-2766?
CVE-2023-2766 affects Weaver Office Automation and Weaver E-office OA, both versions 9.5.
What type of attack can be executed with CVE-2023-2766?
An attacker can initiate a remote attack that leads to unauthorized file or directory access due to CVE-2023-2766.
What is the impact of CVE-2023-2766 on data security?
CVE-2023-2766 could lead to unauthorized access to sensitive files, compromising data security.