Description
TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery enabling unauthorized data exfiltration
Action: Immediate Patch
AI Analysis

Impact

TDuck survey form through version 5.3 does not validate webhook URLs or verify form ownership in the WebhookConfigController, allowing an attacker who is already authenticated to attach webhooks to other users' forms. The attacker can configure the webhook URL to point to any external or internal address, causing form submissions to be leaked or sent to attacker-controlled destinations, potentially exposing sensitive data or facilitating further internal access.

Affected Systems

The vulnerability affects TDuckCloud’s tduck‑survey‑form product for all releases up to and including version 5.3. No specific patch version is listed, but any installation of tduck‑survey‑form v5.3 or earlier is susceptible.

Risk and Exploitability

The CVSS base score of 7.1 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with permission to configure webhooks; the attacker can then send arbitrary HTTP requests from the server to attacker‑controlled or internal endpoints, enabling data exfiltration and potentially further compromise of the host or network. The attack vector is likely a local authenticated user within the application or a compromised user account rather than a remote unauthenticated attacker.

Generated by OpenCVE AI on September 18, 2026 at 06:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update tduck-survey-form to the latest release where webhook URL validation or ownership checks are corrected.
  • If an immediate update is not possible, restrict the permission to configure webhooks to trusted users only and implement a whitelist of allowed webhook URL domains in the application configuration.
  • Deploy network monitoring to detect and block outbound HTTP requests from the application to unapproved external addresses, and enable alerts for anomalous webhook activity.

Generated by OpenCVE AI on September 18, 2026 at 06:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tduckcloud
Tduckcloud tduck-survey-form
Vendors & Products Tduckcloud
Tduckcloud tduck-survey-form

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses.
Title TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Webhook URL
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tduckcloud Tduck-survey-form
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:46.651Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92602

cve-icon Vulnrichment

Updated: 2026-09-21T17:43:13.776Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:20.590

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:00:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)