ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-48392
+3 in the same advisory: …48394 …48395 …48393
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key.

Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.

NVD description · AI analysis pending
9.8
group max
<1%
  • kaifa webitr attendance system