Weaver e-office is an OA product launched by Weaver for small and medium-sized organizations. There is an arbitrary file download vulnerability in downfile.php of Weaver e-office. An attacker can use this vulnerability to obtain sensitive files on the server.This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021. Other reference:None