Headline
CVE-2023-34798: gist:e5e6e03613704a2a4107cc6456f1e8e2
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
[CVE-2023-34798]
CVE-2023-34798
[PRODUCT]
weaver e-office
[VERSION]
v9.5
[PROBLEM TYPE]
file upload
[DESCRIPTION]
weaver e-office v9.5 is vulnerable to file upload via UploadProxy.php to upload encrypt payload