RULE(RULE ID:338995)

Rule General Information
Release Date: 2025-06-04
Rule Name: Weaver E-Office webservice upload.php Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver E-Office is a lightweight OA product designed for small and medium-sized enterprises. It features simple deployment, quick launch, and low maintenance costs. It provides ready-to-use functions such as approval, attendance, document management, and project management. There is an arbitrary file upload vulnerability in the upload.php of Weaver E-Office. Attackers can exploit this vulnerability to upload malicious files (such as trojans, malicious scripts, etc.), thereby gaining control of the server, tampering with website content, stealing sensitive data, or launching further network attacks.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.