Vulnerabilities > CVE-2021-41608 - Authorization Bypass Through User-Controlled Key vulnerability in Classapps Selectsurvey.Net

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
classapps
CWE-639

Summary

A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1.

Vulnerable Configurations

Part Description Count
Application
Classapps
1