Reflected Cross-site Scripting In IDAttend’s IDWeb Application

Discovered by Jack Misiura on behalf of The Missing Link Security

Vulnerability Details

Reflected cross-site scripting in the StudentSearch component in IDAttend’s IDWeb application 3.1.013 allows hijacking of a user’s browsing session by attackers who have convinced the said user to click on a malicious link.   

Affected Versions

Discovered in: 3.1.013

Fixed Versions

Fixed in: 3.1.053

Latest News