Filtered by vendor Idattend
Subscriptions
Total
30 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-26582 | 1 Idattend | 1 Idweb | 2023-10-28 | 9.1 Critical |
Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers. | ||||
CVE-2023-26581 | 1 Idattend | 1 Idweb | 2023-10-28 | 9.1 Critical |
Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers. | ||||
CVE-2023-26571 | 1 Idattend | 1 Idweb | 2023-10-28 | 7.5 High |
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers. | ||||
CVE-2023-26570 | 1 Idattend | 1 Idweb | 2023-10-28 | 7.5 High |
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | ||||
CVE-2023-26569 | 1 Idattend | 1 Idweb | 2023-10-28 | 9.1 Critical |
Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers. | ||||
CVE-2023-26568 | 1 Idattend | 1 Idweb | 2023-10-28 | 9.1 Critical |
Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers. | ||||
CVE-2023-27260 | 1 Idattend | 1 Idweb | 2023-10-28 | 9.1 Critical |
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers. | ||||
CVE-2023-27259 | 1 Idattend | 1 Idweb | 2023-10-28 | 7.5 High |
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers. | ||||
CVE-2023-27258 | 1 Idattend | 1 Idweb | 2023-10-28 | 7.5 High |
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers. | ||||
CVE-2023-27257 | 1 Idattend | 1 Idweb | 2023-10-28 | 7.5 High |
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers. |