CVE-2023-2766 is a high-severity information disclosure vulnerability affecting Weaver OA 9.5, specifically related to the jx2_config.ini file. This flaw allows an unauthenticated, remote attacker to access sensitive files or directories due to improper handling of the file path. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. While not yet observed in active exploitation, public exploit details are available, including a Nuclei template, and the vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.5CPE matchmatch criteria | cpe:2.3:a:weaver:e-office:9.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.