VYPR
Unrated severityNVD Advisory· Published Oct 25, 2023· Updated Sep 10, 2024

Arbitrary File Upload to Web Root In IDAttend’s IDWeb Application

CVE-2023-26578

Description

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated attackers can upload ASP/ASPX files to the web root in IDAttend IDWeb 3.1.013, leading to remote code execution.

Vulnerability

The IDAttend IDWeb application version 3.1.013 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload dangerous files directly to the web root. The application does not properly validate or restrict the file types that authenticated users can upload, enabling the upload of ASP or ASPX files [1].

Exploitation

An attacker must first have valid authentication credentials for the IDWeb application. Once authenticated, the attacker can use the file upload functionality to upload a malicious ASP or ASPX file to the web root directory. No additional privileges or user interaction beyond the initial authentication are required [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the affected server with the privileges of the web application, typically SYSTEM or NETWORK SERVICE. The uploaded ASP/ASPX file can be accessed via the web server, providing full remote code execution on the vulnerable server [1].

Mitigation

The vulnerability is fixed in IDAttend IDWeb version 3.1.053. Organizations running version 3.1.013 or earlier should upgrade to the fixed version as soon as possible. No workarounds have been publicly disclosed in the available references [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IDAttend/IDWebllm-fuzzy
    Range: =3.1.013
  • IDAttend Pty Ltd/IDWebv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.