Kaifa's vulnerability footprint centers on its WebITR attendance system, a web-based timekeeping and workforce-management product, with disclosures clustering around application input-handling and credential-management defects. The recurring weakness classes—SQL injection, unrestricted file uploads, hard-coded credentials and cryptographic keys, and sensitive error disclosure—reflect common risks in web applications that handle user data and maintain persistent access control. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaifa over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48392CRITICAL Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token param | Dec 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-48394HIGH Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privil | Dec 15, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-48395MEDIUM Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can e | Dec 15, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-48393MEDIUM Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message. | Dec 15, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaifa.
Media articles that mention a CVE ID that affects a product developed by Kaifa — matched by CVE ID, not by vendor name.