VYPR
Vendor

Kaifa Technology

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2023-48392CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…

  • CVE-2023-48394HigDec 15, 2023
    risk 0.57cvss 8.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or…

  • CVE-2023-48395MedDec 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.

  • CVE-2023-48393MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.