PT-2026-93812 · Tduckcloud+1 · Tduck-Survey-Form
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TDuck survey form versions prior to 5.1
Description
An authorization bypass exists in the 'POST /user/form/data/update' endpoint. This issue allows authenticated users to overwrite form submission data belonging to other users. Attackers can identify submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data because the system fails to validate ownership when processing update requests.
Recommendations
Update TDuck survey form to version 5.1 or later.
As a temporary mitigation, restrict access to the 'POST /user/form/data/update' endpoint.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tduck-Survey-Form