Retour à la veille

CVE-2026-100303

Publié : 25 septembre 2026
Modifié : 25 septembre 2026
Lien officiel NVD
Score CVSS
5.4
MEDIUM

Description détaillée

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Références et Patchs