← Vulnerability feed

Vulnerability record · CVE-2023-2766 · published 17 May 2023

CVE-2023-2766: Weaver OA e-office config file exposure via jx2_config.ini

Weaver · E Office

Weaver OA 9.5 exposes the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini, allowing unauthenticated remote retrieval of files or directories. The vendor was contacted but did not respond, and a public exploit has been disclosed, so exposed instances are at immediate risk of configuration and credential leakage.

7.5 CVSS 3.1 High EPSS 54% · top 1.0% CWE-552 · CWE-552
7.5CVSS 3.1 base score, v2 5.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 7.5 with network reachability, no authentication, public exploit, and very high EPSS (98.9th percentile) make this a high-priority exposure despite no KEV listing.

What it is

Weaver OA 9.5 exposes the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini, allowing unauthenticated remote retrieval of files or directories. The vendor was contacted but did not respond, and a public exploit has been disclosed, so exposed instances are at immediate risk of configuration and credential leakage.

Impact

An unauthenticated attacker can read the exposed configuration file and potentially other files or directories, disclosing sensitive configuration data such as credentials or internal paths. This information can be used to further compromise the application or connected systems.

Attack surface

The flaw is reachable remotely over the network via a crafted request to the affected path, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

A public exploit is referenced (Exploit tag on the GitHub advisory), EPSS is 0.54232 (98.9th percentile), and the CVE is not listed in CISA KEV.

What to do

  • Apply the vendor patch or upgrade to a fixed Weaver OA/e-office version; if no patch is available, restrict access to the affected path.
  • Block external access to /building/backmgr/urlpage/mobileurl/configfile/ and similar configuration directories at the web server or WAF.
  • Remove or relocate jx2_config.ini and any other configuration files from web-accessible directories.
  • Rotate any credentials or secrets that may have been stored in the exposed configuration file.
  • Monitor vendor advisories and VDB-229271 for updated remediation guidance since the vendor did not respond.

Detection

  • Search web access logs for requests to /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini or similar config file paths.
  • Alert on HTTP 200 responses to .ini, .config, or .conf files from external IPs.
  • Monitor for scanning activity targeting Weaver OA paths and correlate with known exploit signatures.
  • Review outbound traffic for exfiltration of configuration file contents following suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/8079048q/cve/blob/main/weaveroa.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.229271 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.229271 Permissions RequiredThird Party AdvisoryVDB Entry
https://github.com/8079048q/cve/blob/main/weaveroa.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.229271 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.229271 Permissions RequiredThird Party AdvisoryVDB Entry

Track CVE-2023-2766 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-34798Weaver e-office unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 0.78%9.8CVE-2023-2648Weaver e-office unrestricted file upload vulnerabilityA vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/…EPSS 28%8.8CVE-2023-2647Weaver e-office command injection vulnerabilityA vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroo…EPSS 7.0%7.5CVE-2023-2765Weaver e-office vulnerabilityA vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/Ap…EPSS 2.2%7.2CVE-2024-3227Weaver e-office vulnerabilityA vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /gene…EPSS 0.96%7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed7.5CVE-2020-17519Apache Flink JobManager REST interface arbitrary file readA change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to f…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2023-2766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.