Vulnerability record · CVE-2023-2766 · published 17 May 2023
CVE-2023-2766: Weaver OA e-office config file exposure via jx2_config.ini
Weaver · E Office
Weaver OA 9.5 exposes the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini, allowing unauthenticated remote retrieval of files or directories. The vendor was contacted but did not respond, and a public exploit has been disclosed, so exposed instances are at immediate risk of configuration and credential leakage.
Description
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, public exploit, and very high EPSS (98.9th percentile) make this a high-priority exposure despite no KEV listing.
What it is
Weaver OA 9.5 exposes the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini, allowing unauthenticated remote retrieval of files or directories. The vendor was contacted but did not respond, and a public exploit has been disclosed, so exposed instances are at immediate risk of configuration and credential leakage.
Impact
An unauthenticated attacker can read the exposed configuration file and potentially other files or directories, disclosing sensitive configuration data such as credentials or internal paths. This information can be used to further compromise the application or connected systems.
Attack surface
The flaw is reachable remotely over the network via a crafted request to the affected path, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
A public exploit is referenced (Exploit tag on the GitHub advisory), EPSS is 0.54232 (98.9th percentile), and the CVE is not listed in CISA KEV.
What to do
- Apply the vendor patch or upgrade to a fixed Weaver OA/e-office version; if no patch is available, restrict access to the affected path.
- Block external access to /building/backmgr/urlpage/mobileurl/configfile/ and similar configuration directories at the web server or WAF.
- Remove or relocate jx2_config.ini and any other configuration files from web-accessible directories.
- Rotate any credentials or secrets that may have been stored in the exposed configuration file.
- Monitor vendor advisories and VDB-229271 for updated remediation guidance since the vendor did not respond.
Detection
- Search web access logs for requests to /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini or similar config file paths.
- Alert on HTTP 200 responses to .ini, .config, or .conf files from external IPs.
- Monitor for scanning activity targeting Weaver OA paths and correlate with known exploit signatures.
- Review outbound traffic for exfiltration of configuration file contents following suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/8079048q/cve/blob/main/weaveroa.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.229271 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.229271 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://github.com/8079048q/cve/blob/main/weaveroa.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.229271 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.229271 | Permissions RequiredThird Party AdvisoryVDB Entry |
Track CVE-2023-2766 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.