CVE-2023-26582
- EPSS 0.15%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:51:47
Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27377
- EPSS 0.31%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:47
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
CVE-2023-27376
- EPSS 0.31%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:47
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
CVE-2023-27375
- EPSS 0.31%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:46
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
CVE-2023-27262
- EPSS 0.15%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:33
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27261
- EPSS 0.2%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:33
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
CVE-2023-27260
- EPSS 0.15%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:32
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27259
- EPSS 0.36%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:32
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
CVE-2023-27258
- EPSS 0.36%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:32
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.
CVE-2023-27257
- EPSS 0.36%
- Veröffentlicht 25.10.2023 18:17:26
- Zuletzt bearbeitet 21.11.2024 07:52:32
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.