PT-2021-7661 · Unknown · Checkbox Survey

Published

2021-05-25

·

Updated

2025-10-24

·

CVE-2021-27852

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Checkbox Survey versions prior to 7.
Description The issue is related to the deserialization of untrusted data in the CheckboxWeb.dll library of the Checkbox Survey software. This allows a remote attacker to execute arbitrary code.
Recommendations For versions prior to 7, update to version 7 or later to resolve the issue. As a temporary workaround, consider restricting access to the CheckboxWeb.dll library to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-01063
CVE-2021-27852

Affected Products

Checkbox Survey