QID 731228
Date Published: 2024-03-14
QID 731228: Novi Survey Arbitrary Code Execution Vulnerability
Novi Survey is a provider of online survey software created in 2006
CVE-2023-29492: This vulnerability allows remote attackers to execute arbitrary code on the server in the context of the service account on affected installations of Novi Survey.
Affected Versions:
Novi Survey versions prior to 8.9.43676
QID Detection Logic:
Unauthenticated: This QID checks for "Novi Survey JavaScript" hyperlink on the webpage along with version.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade the installation to version 8.9.43676 or greater. Please refer to Novi Survey security advisory Apr-2023 for further information.
Vendor References
- Novi Survey Security Advisory -
novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx
CVEs related to QID 731228
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Novi Survey Security Advisory |
|