CVE-2023-37756: I-Doit
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
Affected products
- I-Doit I-Doit: up to and including 25
Published 2023-09-14. Last modified 2026-06-17.