Vulnerability Description
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kaifa | Webitr Attendance System | 2.1.0.23 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7622-57e5f-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7622-57e5f-1.htmlThird Party Advisory
FAQ
What is CVE-2023-48392?
CVE-2023-48392 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit thi...
How severe is CVE-2023-48392?
CVE-2023-48392 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-48392?
Check the references section above for vendor advisories and patch information. Affected products include: Kaifa Webitr Attendance System.