TDuck 调查表单(version 5.0 及更早版本)在 POST /user/form/data/update 端点中存在一个授权绕过漏洞,允许经过身份验证的用户覆盖其他用户的表单提交数据。攻击者可以发现以狭窄范围分配的提交标识符,并在没有所有权验证的情况下发送更新请求,从而修改包含个人数据的任意表单响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TDuckCloud | tduck-survey-form | 0 ~ 5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet