TDuck 调查表单系统 6.0 版本中,FormAuthUtils.hasPermission 方法存在信息泄露漏洞。当请求的表单不存在时,该权限检查机制未能正确拒绝访问(即“失败时默认开放”),导致已认证的用户能够访问已删除的表单提交数据。攻击者在表单被永久删除后,通过向 GET /user/form/data/details 接口提供已知的数据 ID(dataId),即可读取孤儿化的提交数据,其中可能包含个人隐私信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TDuckCloud | tduck-survey-form | 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100303 | 5.4 MEDIUM | TDuck survey form through 6.0 Missing Authorization in Form Theme Management Endpoints |
| CVE-2026-100306 | 5.3 MEDIUM | TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement |
| CVE-2026-100305 | 4.3 MEDIUM | TDuck survey form through 6.0 Fill-In Restriction Bypass via Authenticated Submission Endp |
No comments yet