PT-2023-20737 · Idweb · Idweb

Melodi Dey

·

Published

2023-10-25

·

Updated

2024-09-25

·

CVE-2023-26571

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IDWeb application versions 3.1.052 and earlier
Description The issue concerns missing authentication in the SetStudentNotes method, allowing unauthenticated attackers to modify student data.
Recommendations For IDWeb application versions 3.1.052 and earlier, update to a version that includes proper authentication for the SetStudentNotes method to prevent unauthorized modification of student data. As a temporary workaround, consider restricting access to the SetStudentNotes method until a patch is available.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-26571

Affected Products

Idweb