Impact
DWSurvey version 6.14.0 contains an authentication bypass flaw that can be triggered through the '/api/dwsurvey/none/' and '/api/dwsurvey/up/' endpoints, allowing users to interact with the survey system without valid credentials. Based on the description, no authentication header is required to access these endpoints, implying an unauthenticated HTTP request can trigger the bypass. The flaw undermines confidentiality and integrity of survey data and may grant attackers the ability to read, modify or delete entries.
Affected Systems
The affected product is DWSurvey v6.14.0. No specific vendor information is provided in the advisory. Because the vendor is omitted, it is inferred that the vulnerability applies to all installations of this version regardless of vendor.
Risk and Exploitability
The vulnerability is exploitable over the network via the exposed API calls; no authentication is required to trigger the bypass. Because an external attacker can send an HTTP request directly to the aforementioned endpoints, the risk is significant, and the CVSS score of 9.8 classifies this flaw as critical. The EPSS score is < 1% and it is not listed in CISA's KEV catalog, which suggests a lower baseline exploitation probability, but the impact of successful exploitation remains high. The likely attack vector is an unauthenticated network request to the specified API endpoints.
OpenCVE Enrichment