VYPR
Unrated severityNVD Advisory· Published Oct 25, 2023· Updated Sep 25, 2024

Missing Authentication In IDAttend’s IDWeb Application

CVE-2023-27258

Description

Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IDAttend IDWeb 3.1.052 and earlier lacks authentication in the GetStudentGroupStudents method, allowing unauthenticated attackers to retrieve student and teacher data.

Vulnerability

The IDAttend IDWeb application version 3.1.052 and earlier contains a missing authentication vulnerability in the GetStudentGroupStudents method. This method does not enforce any access control, allowing unauthenticated attackers to invoke it directly. The vulnerability affects all versions up to and including 3.1.052, as confirmed in the advisory [1].

Exploitation

An unauthenticated attacker with network access to the IDWeb application can send crafted HTTP requests to the vulnerable GetStudentGroupStudents endpoint. No authentication, session token, or prior user interaction is required. The advisory does not detail the exact request format, but the method is exposed over the web interface [1].

Impact

Successful exploitation allows an unauthenticated attacker to extract sensitive student and teacher data, including personally identifiable information (PII). This results in a breach of confidentiality (CIA impact: confidentiality). The attacker does not gain write access or code execution, but the exposed data could be used for further attacks or sold [1].

Mitigation

The vulnerability is fixed in IDAttend IDWeb version 3.1.053, released according to the advisory. Users must upgrade to version 3.1.053 or later. No workaround is available for older versions. The vendor should be contacted if immediate patching is not possible [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IDAttend/IDWebllm-fuzzy
    Range: <=3.1.052
  • IDAttend Pty Ltd/IDWebv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.