VYPR
Unrated severityNVD Advisory· Published Dec 15, 2023· Updated Oct 14, 2024

Kaifa Technology WebITR - Hard-coded Cryptographic Key

CVE-2023-48392

Description

Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.