PT-2023-7880 · Kaifa Technology · Webitr

Cyku

·

Published

2023-12-15

·

Updated

2024-10-14

·

CVE-2023-48392

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kaifa Technology WebITR (affected versions not specified)
Description The issue is related to the use of a hard-coded encryption key in the WebITR online attendance system. This allows an unauthenticated remote attacker to generate a valid token parameter and exploit the vulnerability to access the system with an arbitrary user account, including the administrator's account. The attacker can then execute the login account's permissions and obtain relevant information. The vulnerability can be exploited to elevate privileges to the level of an administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2023-08951
CVE-2023-48392

Affected Products

Webitr