CVE-2023-27259

HIGH

idattend idweb < 3.1.052 - Unauthenticated Sensitive Data Exposure via GetAssignmentsDue Method

Title source: llm
STIX 2.1

Description

Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 39.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
idattend/idweb < 3.1.052
Published Oct 25, 2023
Tracked Since Feb 18, 2026