Idattend develops a focused vulnerability footprint centered on its IdWeb web-based access and management platform, which appears to serve identity and attendance management functions in enterprise environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur consistently across a narrow product portfolio through authentication, input-validation, and access-control weakness classes—missing authentication for critical functions, SQL injection, cross-site scripting, and improper disclosure of sensitive files—that are characteristic of web applications handling sensitive credential and attendance data. The concentration of critical-severity flaws in a widely deployed web platform used to manage identity systems represents a high-priority attack surface for defenders tracking this vendor. Inventory instances of IdWeb and prioritize patches for authentication and injection-related disclosures; live exploitation activity and current severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idattend over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26582CRITICAL Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticat | Oct 25, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-26573CRITICAL Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials. | Oct 25, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-27255CRITICAL Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthentic | Oct 25, 2023 | 9.1 | 26 | NO | NO |
CVE-2023-27262CRITICAL Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenti | Oct 25, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-27254CRITICAL Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated | Oct 25, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-26584CRITICAL Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unaut | Oct 25, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-26578HIGH Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining comm | Oct 25, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-26572CRITICAL Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated at | Oct 25, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-26569CRITICAL Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unaut | Oct 25, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-26568CRITICAL Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthentic | Oct 25, 2023 | 9.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idattend.
Media articles that mention a CVE ID that affects a product developed by Idattend — matched by CVE ID, not by vendor name.