CVE-2023-29492

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:3rdmill:novi_survey:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx - Vendor Advisory () https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx - Vendor Advisory

26 Sep 2024, 14:10

Type Values Removed Values Added
First Time 3rdmill novi Survey
3rdmill
CPE cpe:2.3:a:novisurvey:novi_survey:*:*:*:*:*:*:*:* cpe:2.3:a:3rdmill:novi_survey:*:*:*:*:*:*:*:*

Information

Published : 2023-04-11 05:15

Updated : 2024-11-21 07:57


NVD link : CVE-2023-29492

Mitre link : CVE-2023-29492

CVE.ORG link : CVE-2023-29492


JSON object : View

Products Affected

3rdmill

  • novi_survey
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')