Fanwei E-office unauth file upload RCE (CVE-2022-50993)
CVE-2022-50993
CVE-2022-50993: Unauthenticated arbitrary file upload in Fanwei E-office before 10.0_20221201 leads to RCE. CVSS 9.8. Update to version 10.0_20221201 or later.
Patch now - CVE-2022-50993 is a critical unauthenticated file upload vulnerability in Fanwei (Weaver) E-office versions prior to 10.0_20221201 that allows remote attackers to achieve remote code execution by uploading a PHP webshell. Exploitation evidence was first observed on 2022-10-10, and a patch is available in version 10.0_20221201.
Overview
CVE-2022-50993 affects the OfficeServer.php endpoint in Weaver (Fanwei) E-office, a widely used office automation suite in Chinese-speaking regions. The vulnerability stems from insufficient file type validation when processing multipart POST requests. An unauthenticated attacker can upload files with arbitrary filenames and disguised MIME types directly to the Document directory.
Once a malicious PHP file is uploaded, the attacker executes it via a simple HTTP GET request, achieving remote code execution with the privileges of the web server user. This allows full compromise of the application and underlying server.
Impact
- CVSS 9.8 (Critical) - no authentication or user interaction required
- Attack complexity: Low - exploitation requires only a crafted HTTP request
- Result: Complete loss of confidentiality, integrity, and availability
- Risk: Potential lateral movement within the internal network if the web server is not properly segmented
Remediation
- Immediate action: Upgrade Fanwei E-office to version 10.0_20221201 or later. This patch adds proper file type validation and restricts upload destinations.
- Mitigation (if patching is delayed): Restrict network access to the OfficeServer.php endpoint to trusted IP ranges only. Monitor web server logs for unexpected file uploads to the Document directory, particularly .php and .phtml files.
- Detection: Look for POST requests to OfficeServer.php with suspicious file extensions in the filename parameter. Check the Document directory for unauthorized PHP files.
Security Insight
This vulnerability echoes a recurring pattern in enterprise office software: developers prioritize ease of file sharing over security validation. Fanwei E-office’s file upload mechanism relied on trusting client-supplied content types rather than validating file contents server-side - a mistake that has caused similar RCE vulnerabilities in products like Seeyon and Landray. Organizations running Chinese OA suites should treat file upload endpoints as critical attack surface, applying strict allowlists for file extensions and MIME types at the application layer, not the logic layer.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions u...
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_ac...
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....