S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-2766 Scanner

Detects 'Directory Traversal' vulnerability in Weaver OA affects v. 9.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2766
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
OAby Weaver
9.5
Updated Aug 22, 2026View on NVD →
Detail

Weaver OA 9.5 is a popular application that is used by many businesses and organizations for managing and monitoring their buildings and facilities. It is a powerful tool that simplifies the complex process of building management by bringing everything under one digital umbrella. Using Weaver OA, building managers can easily check different parameters such as energy usage, water consumption, temperature, and humidity, among others. The application allows them to automate tasks, receive alerts, and schedule maintenance checks to ensure everything is running smoothly. 

Recently, a dangerous vulnerability has been detected in Weaver OA version 9.5, which has been classified as problematic. The vulnerability code is CVE-2023-2766, and it affects some of the processing that occurs in the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. This file contains sensitive information such as passwords and configurations, and the manipulation of it by attackers can lead to the exposure of files or directories that are supposed to be inaccessible. 

If exploited, this vulnerability can have severe consequences for businesses and organizations using Weaver OA. Attackers can gain access to private and sensitive data, which can be used for blackmail, espionage, or other malicious purposes. In addition, attackers can use this vulnerability to execute arbitrary code on the affected system, which can lead to the complete compromise of the system, or even the entire network. 

In conclusion, the CVE-2023-2766 vulnerability in Weaver OA version 9.5 is a significant threat that organizations need to be aware of and take precautions against. By updating the application, applying access controls, monitoring for suspicious activity, and using strong authentication measures, businesses can mitigate the risk of a cyberattack. Subscribing to the pro features of s4e.io can help streamline this process and enhance security even further.

 

REFERENCES

Solution Advice

Fortunately, there are some precautions that businesses and organizations can take to protect themselves against this vulnerability. Here are some suggestions: 

- Update to the latest version of Weaver OA, as the vendor may have already patched this vulnerability. 
- Check access permissions for the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini and ensure that it can only be accessed by authorized users. 
- Monitor the system and network for any suspicious activity, using a robust threat detection and response platform. 
- Implement strong passwords and multifactor authentication to limit the risk of unauthorized access to the system. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.