CVE-2023-48392: Kaifa Webitr Attendance System
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.
Affected products
- Kaifa Webitr Attendance System: version 2.1.0.23 only
Published 2023-12-15. Last modified 2026-06-17.