CVE-2023-29492
Published on: Not Yet Published
Last Modified on: 04/18/2023 02:16:00 AM UTC
Certain versions of Novi Survey from Novisurvey contain the following vulnerability:
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
- CVE-2023-29492 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
novi survey security advisory apr 2023 | Vendor Advisory novisurvey.net text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Novisurvey | Novi Survey | All | All | All | All |
- cpe:2.3:a:novisurvey:novi_survey:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-29492 : Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in th… twitter.com/i/web/status/1… | 2023-04-11 05:01:54 |
![]() |
Potentially Critical CVE Detected! CVE-2023-29492 Novi Survey before 8.9.43676 allows remote attackers to execute a… twitter.com/i/web/status/1… | 2023-04-11 06:10:59 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - A Vulnerability in Novi Survey Could Allow for Arbitrary Code Execution - PATCH NOW | 2023-04-20 14:43:27 |