IDAttend IDWeb是IDAttend公司的一个基于网络的模块。 IDAttend IDWeb 3.1.052 版本及之前版本存在安全漏洞,该漏洞源于 StudentSearch 组件存在反射型跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IDAttend Pty Ltd | IDWeb | 0 ~ 3.1.052 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-26569 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-27262 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-27260 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-27255 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-27254 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26584 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26583 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26582 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26581 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26568 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26572 | 9.8 CRITICAL | Unauthenticated SQL Injection In IDAttend’s IDWeb Application |
| CVE-2023-26578 | 8.8 HIGH | Arbitrary File Upload to Web Root In IDAttend’s IDWeb Application |
| CVE-2023-26573 | 8.2 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-27377 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-26577 | 7.5 HIGH | Stored Cross-site Scripting In IDAttend’s IDWeb Application |
| CVE-2023-27376 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-27375 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-26570 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-27259 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
| CVE-2023-27258 | 7.5 HIGH | Missing Authentication In IDAttend’s IDWeb Application |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet