Impact
The vulnerability is an authorization bypass that allows any authenticated user to overwrite the form submission data of another user via the POST /user/form/data/update endpoint. Because the endpoint does not verify submission ownership, an attacker who can discover the narrow-range identifiers can submit arbitrary updates that replace personal data, potentially changing sensitive information without consent.
Affected Systems
Version 5.0 or earlier of the TDuckCloud "tduck-survey-form" product is affected. No additional patch versions are listed in the CNA data; therefore any installation of 5.0 or earlier should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, because the endpoint is exposed over the web, remote attackers with valid credentials can exploit the flaw once they identify a submission ID, which is readily discoverable due to its narrow range. The lack of ownership validation directly enables the malicious overwrite of user data.
OpenCVE Enrichment