Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.
Critical information retrieved:
* APIKEY (1 year user Session)
* RefreshToken (10 minutes user Session)
* Password hashed with bcrypt
* User IP
* Email
* Full Name
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ngsurvey
Ngsurvey ngsurvey |
|
| Vendors & Products |
Ngsurvey
Ngsurvey ngsurvey |
Mon, 01 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurveyallows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name |
Mon, 01 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurveyallows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TCS-CERT
Published: 2025-12-01T15:47:10.317Z
Updated: 2025-12-01T16:16:34.168Z
Reserved: 2025-12-01T15:30:15.569Z
Link: CVE-2025-13829
Updated: 2025-12-01T16:05:22.761Z
Status : Awaiting Analysis
Published: 2025-12-01T16:15:51.690
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13829
No data.