CVE-2022-46484

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
References
Link Resource
https://github.com/WodenSec/CVE-2022-46484 Third Party Advisory
https://github.com/WodenSec/CVE-2022-46484 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ngsurvey:ngsurvey:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:30

Type Values Removed Values Added
Summary
  • (es) Divulgación de información en encuestas protegidas mediante contraseña en Data Illusion Survey Software Solutions NGSurvey v2.4.28 e inferiores permite a los atacantes ver la contraseña para acceder y enviar encuestas arbitrariamente.
References () https://github.com/WodenSec/CVE-2022-46484 - Third Party Advisory () https://github.com/WodenSec/CVE-2022-46484 - Third Party Advisory

Information

Published : 2023-08-02 15:15

Updated : 2024-11-21 07:30


NVD link : CVE-2022-46484

Mitre link : CVE-2022-46484

CVE.ORG link : CVE-2022-46484


JSON object : View

Products Affected

ngsurvey

  • ngsurvey
CWE
CWE-922

Insecure Storage of Sensitive Information