Impact
OpnForm generates editable‑submission secrets by hashing sequential row identifiers with Hashids using an empty default salt. This weakness allows an unauthenticated attacker to compute any secret hash, thereby accessing or overwriting others’ submissions through the submission‑fetch and answer endpoints. The effect is disclosure of confidential respondent data or alteration of submission content without authorization.
Affected Systems
The affected product is OpnForm. No specific version information is provided in the CNA data, so all installations of OpnForm may be at risk.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is rated critical. Exploitation requires only the public network and the ability to guess or compute the hash, which is trivial when the salt is empty. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, exploitation could occur at any time. Attackers can read other respondents’ full data or overwrite their own entries by supplying the predicted hash values.
OpenCVE Enrichment