Infigosoftware develops a staff and attendance management portal platform, with the durable vulnerability signal centered on cross-site request forgery (CSRF) weaknesses in web-session handling. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infigosoftware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0761MEDIUM The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in | May 15, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-0763MEDIUM The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admin | May 15, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0762MEDIUM The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in a | May 15, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infigosoftware.
Media articles that mention a CVE ID that affects a product developed by Infigosoftware — matched by CVE ID, not by vendor name.