PT-2023-7880 · Kaifa Technology · Webitr
Cyku
·
Published
2023-12-15
·
Updated
2024-10-14
·
CVE-2023-48392
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kaifa Technology WebITR (affected versions not specified)
Description
The issue is related to the use of a hard-coded encryption key in the WebITR online attendance system. This allows an unauthenticated remote attacker to generate a valid token parameter and exploit the vulnerability to access the system with an arbitrary user account, including the administrator's account. The attacker can then execute the login account's permissions and obtain relevant information. The vulnerability can be exploited to elevate privileges to the level of an administrator.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webitr