CVE-2023-26580

HIGH

IDAttend's IDWeb <3.1.013 - Info Disclosure

Title source: llm
STIX 2.1

Description

Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552 CWE-306
Status published
Products (1)
idattend/idweb < 3.1.052
Published Oct 25, 2023
Tracked Since Feb 18, 2026