PT-2023-20747 · Idattend · Idweb

Jack Misiura

·

Published

2023-10-25

·

Updated

2023-10-28

·

CVE-2023-26580

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IDWeb application version 3.1.013
Description The issue allows unauthenticated attackers to retrieve any file present on the web server. This is due to an unauthenticated arbitrary file read in the IDAttend’s IDWeb application.
Recommendations For version 3.1.013, consider restricting access to sensitive files on the web server until a patch is available. As a temporary workaround, disabling the file retrieval functionality can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Missing Authentication

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26580

Affected Products

Idweb