Description
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 2_1_0_23 or latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52447 | Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7625-a0b9c-1.html |
|
History
Wed, 21 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-21T14:25:53.216Z
Reserved: 2023-11-16T04:08:17.029Z
Link: CVE-2023-48395
Updated: 2024-08-02T21:30:34.998Z
Status : Modified
Published: 2023-12-15T10:15:08.590
Modified: 2024-11-21T08:31:37.847
Link: CVE-2023-48395
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD