📦 Idweb

by Idattend

🔍 What is Idweb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-26581

CRITICAL CVSS 9.8 Oct 25, 2023

Unauthenticated SQL injection in IDAttend's IDWeb application allows attackers to extract or modify all database data without credentials. This affects IDWeb versions 3.1.052 and earlier, putting orga...

CVE-2023-26583

CRITICAL CVSS 9.8 Oct 25, 2023

Unauthenticated SQL injection vulnerability in IDAttend's IDWeb application allows attackers to extract or modify all database data without authentication. This affects IDWeb version 3.1.052 and earli...

CVE-2023-27254

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on IDAttend's IDWeb application. Attackers can extract or modify all data in the database without needing credentia...

CVE-2023-27260

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or modify all data in the database without needing cred...

CVE-2023-27262

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or modify all data in the database without needing vali...

CVE-2023-26568

CRITICAL CVSS 9.8 Oct 25, 2023

Unauthenticated attackers can execute arbitrary SQL queries against IDAttend's IDWeb application, potentially extracting or modifying all database data. This affects all users running IDWeb version 3....

CVE-2023-26572

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows unauthenticated attackers to perform SQL injection attacks against IDAttend's IDWeb application. Attackers can extract or modify all data in the database without needing cred...

CVE-2023-27257

HIGH CVSS 7.5 Oct 25, 2023

This vulnerability allows unauthenticated attackers to retrieve student information from IDAttend's IDWeb application by exploiting missing authentication in the GetActiveToiletPasses method. It affec...

CVE-2023-27259

HIGH CVSS 7.5 Oct 25, 2023

This vulnerability allows unauthenticated attackers to extract sensitive student and teacher data from IDAttend's IDWeb application. It affects organizations using IDWeb version 3.1.052 and earlier du...

CVE-2023-27376

HIGH CVSS 7.5 Oct 25, 2023

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application. It affects organizations using IDWeb version 3.1.052 and earlier. The StudentPo...

CVE-2023-26570

HIGH CVSS 7.5 Oct 25, 2023

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application. It affects organizations using IDWeb version 3.1.052 and earlier. The StudentPo...

CVE-2023-26574

HIGH CVSS 7.5 Oct 25, 2023

CVE-2023-26574 allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application by exploiting missing authentication in the SearchStudents method. This affects orga...

CVE-2023-26576

HIGH CVSS 7.5 Oct 25, 2023

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application by exploiting missing authentication in the SearchStudentsRFID method. It affect...

CVE-2023-26578

HIGH CVSS 8.8 Oct 25, 2023

This vulnerability allows authenticated attackers to upload arbitrary files, including ASP/ASPX web shells, to the web root directory of IDAttend's IDWeb application. Successful exploitation leads to ...

CVE-2023-26580

HIGH CVSS 7.5 Oct 25, 2023

CVE-2023-26580 is an unauthenticated arbitrary file read vulnerability in IDAttend's IDWeb application version 3.1.013. This allows attackers without credentials to read any file on the web server, po...