Vulnerabilities (CVE)

Filtered by vendor Kaifa Subscribe
Filtered by product Webitr Attendance System
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48394 1 Kaifa 1 Webitr Attendance System 2023-12-22 N/A 8.8 HIGH
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.