Impact
TDuck survey form through version 5.3 does not validate webhook URLs or verify form ownership in the WebhookConfigController, allowing an attacker who is already authenticated to attach webhooks to other users' forms. The attacker can configure the webhook URL to point to any external or internal address, causing form submissions to be leaked or sent to attacker-controlled destinations, potentially exposing sensitive data or facilitating further internal access.
Affected Systems
The vulnerability affects TDuckCloud’s tduck‑survey‑form product for all releases up to and including version 5.3. No specific patch version is listed, but any installation of tduck‑survey‑form v5.3 or earlier is susceptible.
Risk and Exploitability
The CVSS base score of 7.1 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with permission to configure webhooks; the attacker can then send arbitrary HTTP requests from the server to attacker‑controlled or internal endpoints, enabling data exfiltration and potentially further compromise of the host or network. The attack vector is likely a local authenticated user within the application or a compromised user account rather than a remote unauthenticated attacker.
OpenCVE Enrichment