CVE-2025-13768: Uniong Webitr
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability.
Affected products
- Uniong Webitr: before 2_1_0_34 (fixed in 2_1_0_34)
Published 2025-11-28. Last modified 2026-10-08.