Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13829

Опубликовано: 01 дек. 2025
Источник: nvd
EPSS Низкий

Описание

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.

Critical information retrieved:

  • APIKEY (1 year user Session)
  • RefreshToken (10 minutes user Session)
  • Password hashed with bcrypt
  • User IP
  • Email
  • Full Name

EPSS

Процентиль: 15%
0.0005
Низкий

Дефекты

CWE-863

Связанные уязвимости

github
2 месяца назад

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name

EPSS

Процентиль: 15%
0.0005
Низкий

Дефекты

CWE-863