PT-2026-93861 · Tduckcloud+1 · Tduck-Survey-Form

·

CVE-2026-92602

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TDuck survey form versions prior to 5.4
Description The WebhookConfigController fails to validate webhook URLs and verify form ownership. This allows authenticated attackers to attach webhooks to forms belonging to other users, enabling the exfiltration of form submissions to arbitrary internal or external addresses.
Recommendations Update to version 5.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92602

Affected Products

Tduck-Survey-Form