RULE(RULE ID:331173)

Rule General Information
Release Date: 2020-09-15
Rule Name: Weaver e-Bridge Middleware Arbitrary File Reading Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver provides mobile office, WeChat office, collaborative office (OA), process management, information portal, knowledge management, cost control management and other functions. It is suitable for mobile phones and PC terminals and is one of the mainstream OA systems today. There is an arbitrary file reading vulnerability on the Pan>Wei e-Bridge platform. The attacker can obtain the filepath through the /wxjsapi/saveYZJFile interface, and return the absolute path of the program in the data packet. The attacker can identify the program running path by returning the content Path to download the database configuration file.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.