CVE-2023-27262: Idattend Idweb
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
Affected products
- Idattend Idweb: up to and including 3.1.052
Published 2023-10-25. Last modified 2026-06-17.