PT-2023-20737 · Idweb · Idweb

Melodi Dey

·

Publicado

2023-10-25

·

Atualizado

2024-09-25

·

CVE-2023-26571

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IDWeb application versions 3.1.052 and earlier
Description The issue concerns missing authentication in the SetStudentNotes method, allowing unauthenticated attackers to modify student data.
Recommendations For IDWeb application versions 3.1.052 and earlier, update to a version that includes proper authentication for the SetStudentNotes method to prevent unauthorized modification of student data. As a temporary workaround, consider restricting access to the SetStudentNotes method until a patch is available.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26571

Produtos afetados

Idweb