PT-2023-20745 · Idweb · Idweb

Jack Misiura

·

Published

2023-10-25

·

Updated

2023-10-28

·

CVE-2023-26579

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions IDWeb application version 3.1.013
Description The issue concerns missing authentication in the DeleteStaff method, allowing unauthenticated attackers to delete staff information.
Recommendations For version 3.1.013, ensure proper authentication is implemented for the DeleteStaff method to prevent unauthorized access.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-26579

Affected Products

Idweb