Impact
The vulnerability resides in the Survey Status Handler component of diaowen DWSurvey, where an unknown function within the /api/dwsurvey/app/survey/up-survey-status.do endpoint can be manipulated to bypass normal authorization controls (CWE-266, CWE-285). The flaw allows remote exploitation by sending crafted requests, enabling an attacker who can reach the endpoint to alter or view survey status information without proper authentication, potentially leading to unauthorized data disclosure or privilege elevation.
Affected Systems
All installations of diaowen DWSurvey up to version 6.14.0 are affected, regardless of deployment configuration, since the flaw exists in the Survey Status Handler of those releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. The EPSS score is under 1%, suggesting a low probability of immediate exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted requests to the endpoint; no local access or privileged credentials are required, making the threat realistic in environments where the endpoint is exposed to untrusted networks.
OpenCVE Enrichment