Unrated severityNVD Advisory· Published Dec 15, 2023· Updated Oct 14, 2024
Kaifa Technology WebITR - Hard-coded Cryptographic Key
CVE-2023-48392
Description
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.
Affected products
1- Range: 2_1_0_19
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.