CVE-2023-26578

HIGH

IDAttend's IDWeb <3.1.013 - Command Injection

Title source: llm
STIX 2.1

Description

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-434
Status published
Products (1)
idattend/idweb 3.1.013
Published Oct 25, 2023
Tracked Since Feb 18, 2026