Impact
TDuck survey form through version 6.0 does not validate write passwords on submission endpoints, performing the check only on the client side. As a result, remote attackers can submit data to public form‑submission APIs without providing the write password, effectively inserting arbitrary entries into surveys. The weakness, identified as CWE‑602, permits unauthorized data modification which can compromise the integrity of the collected information and potentially expose sensitive data to unintended recipients.
Affected Systems
The vulnerability affects all TDuckCloud TDuck survey form deployments up to and including version 6.0. Users running any of these versions without applying a later, patched release are susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting exploitation is currently not widespread. Nonetheless, the flaw is exploitable by any unauthenticated actor who can obtain a form key from a share link, enabling them to target the public submission endpoints directly. No special network or application privileges are required beyond access to the form key, which is often freely distributed.
OpenCVE Enrichment