PT-2022-11440 · Unknown · Selectsurvey.Net

Garrett Foster

·

Published

2022-01-28

·

Updated

2022-07-12

·

CVE-2021-41608

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SelectSurvey.NET versions prior to 5.052.000
Description A file disclosure issue allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the ID parameter in sequential order beginning from 1 in the "UploadedImageDisplay.aspx" endpoint.
Recommendations For versions prior to 5.052.000, update to version 5.052.000 or later to resolve the issue. As a temporary workaround, consider restricting access to the UploadedImageDisplay.aspx endpoint until a patch is applied. Avoid using sequential ID values in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41608

Affected Products

Selectsurvey.Net