PT-2023-20747 · Idattend · Idweb

Jack Misiura

·

Publicado

2023-10-25

·

Atualizado

2023-10-28

·

CVE-2023-26580

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IDWeb application version 3.1.013
Description The issue allows unauthenticated attackers to retrieve any file present on the web server. This is due to an unauthenticated arbitrary file read in the IDAttend’s IDWeb application.
Recommendations For version 3.1.013, consider restricting access to sensitive files on the web server until a patch is available. As a temporary workaround, disabling the file retrieval functionality can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Missing Authentication

Files Accessible to External Parties

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26580

Produtos afetados

Idweb