VYPR
Unrated severityNVD Advisory· Published Oct 25, 2023· Updated Sep 11, 2024

Unauthenticated SQL Injection In IDAttend’s IDWeb Application

CVE-2023-26583

Description

Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated SQL injection in IDAttend IDWeb's GetCurrentPeriod method allows full database extraction or modification; fixed in version 3.1.053.

Vulnerability

An unauthenticated SQL injection vulnerability exists in the GetCurrentPeriod method of IDAttend's IDWeb application. Versions 3.1.052 and earlier are affected, with the issue discovered in version 3.1.013 [1]. The vulnerability allows an attacker to inject arbitrary SQL queries via the method's input parameters without requiring any authentication.

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the GetCurrentPeriod endpoint with malicious SQL payloads. No authentication or prior access is needed. The attacker only needs network access to the vulnerable application.

Impact

Successful exploitation enables an unauthenticated attacker to extract or modify all data stored in the underlying database. This includes sensitive information such as user credentials, personal data, and application configuration, leading to a complete compromise of data confidentiality and integrity.

Mitigation

The issue is fixed in IDWeb version 3.1.053 [1]. Users should upgrade to this version or later immediately. No workarounds are documented. If upgrading is not possible, restrict network access to the application as a temporary measure.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IDAttend/IDWebllm-fuzzy
    Range: <=3.1.052
  • IDAttend Pty Ltd/IDWebv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.