VYPR
Unrated severityNVD Advisory· Published Oct 25, 2023· Updated Sep 25, 2024

Missing Authentication In IDAttend’s IDWeb Application

CVE-2023-27376

Description

Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authentication in IDAttend's IDWeb application allows unauthenticated attackers to extract sensitive student data.

Vulnerability

Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend's IDWeb application versions 3.1.052 and earlier (discovered in 3.1.013) allows unauthenticated access to sensitive student data [1].

Exploitation

An unauthenticated attacker can trigger the vulnerable method to retrieve student details without any authentication or user interaction [1].

Impact

Successful exploitation leads to extraction of sensitive student data, resulting in a breach of confidentiality [1].

Mitigation

The issue is fixed in IDWeb version 3.1.053. Organizations should update to the latest version [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IDAttend/IDWebllm-fuzzy
    Range: <=3.1.052
  • IDAttend Pty Ltd/IDWebv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.