CVE-2023-48392: Kaifa Webitr Attendance System

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.

Affected products

  • Kaifa Webitr Attendance System: version 2.1.0.23 only

Published 2023-12-15. Last modified 2026-06-17.