Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
References
Link | Resource |
---|---|
https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-11T00:00:00
Updated: 2023-04-11T00:00:00
Reserved: 2023-04-07T00:00:00
Link: CVE-2023-29492
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-11T05:15:07.393
Modified: 2023-04-18T02:16:54.183
Link: CVE-2023-29492
JSON object: View
Redhat Information
No data.
CWE