Impact
DWSurvey version 6.14.0 contains an authentication bypass flaw that can be triggered through the '/api/dwsurvey/none/' and '/api/dwsurvey/up/' endpoints, allowing users to interact with the survey system without valid credentials. The flaw undermines confidentiality and integrity of survey data and may grant attackers the ability to read, modify or delete entries.
Affected Systems
The affected product is DWSurvey v6.14.0. No specific vendor information is provided in the advisory, but the vulnerability applies to all installations running this version.
Risk and Exploitability
The vulnerability is exploitable over the network via the exposed API calls; no authentication is required to trigger the bypass. Because an external attacker can send an HTTP request directly to the aforementioned endpoints, the risk is significant, although an official CVSS score is not available. The EPSS score is not disclosed and it is not listed in CISA's KEV catalog, which suggests a lower baseline exploitation probability but the impact of successful exploitation remains high.
OpenCVE Enrichment