CVE-2022-46484

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
References
Link Resource
https://github.com/WodenSec/CVE-2022-46484 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ngsurvey:ngsurvey:*:*:*:*:*:*:*:*

History

07 Aug 2023, 16:07

Type Values Removed Values Added
First Time Ngsurvey
Ngsurvey ngsurvey
CPE cpe:2.3:a:ngsurvey:ngsurvey:*:*:*:*:*:*:*:*
CWE CWE-922
References (MISC) https://github.com/WodenSec/CVE-2022-46484 - (MISC) https://github.com/WodenSec/CVE-2022-46484 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

02 Aug 2023, 16:55

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-02 15:15

Updated : 2023-12-10 15:14


NVD link : CVE-2022-46484

Mitre link : CVE-2022-46484

CVE.ORG link : CVE-2022-46484


JSON object : View

Products Affected

ngsurvey

  • ngsurvey
CWE
CWE-922

Insecure Storage of Sensitive Information