Metrics
Affected Vendors & Products
Tue, 04 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization | |
| First Time appeared |
Diaowen
Diaowen dwsurvey |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:diaowen:dwsurvey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Diaowen
Diaowen dwsurvey |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-08-04T03:00:08.926Z
Updated: 2026-08-04T14:20:14.881Z
Reserved: 2026-08-03T17:50:34.988Z
Link: CVE-2026-18722
Updated: 2026-08-04T14:20:10.884Z
Status : Deferred
Published: 2026-08-04T04:16:32.280
Modified: 2026-08-12T20:59:00.027
Link: CVE-2026-18722
No data.