Executive brief
TDuckCloud is a platform used by businesses to create and manage online forms and surveys. A critical security flaw in version 5.1 allows an attacker to manipulate the system's database by sending specially crafted requests to the file upload module. This could lead to the theft of sensitive customer data, unauthorized modification of records, or complete takeover of the server.
Technical details
A SQL injection vulnerability exists in TDuckCloud v.5.1 within the file download functionality of the form data module. Specifically, the 'formKey' parameter in the '/user/form/data/download/file' API endpoint is susceptible to error-based SQL injection (e.g., using the 'updatexml' function). An unauthenticated remote attacker can exploit this by sending a crafted JSON POST request to extract sensitive information from the database or potentially achieve remote code execution depending on the database configuration. The vulnerability is triggered when interacting with the 'Add a file upload' module during data retrieval.
Affected products
- TDuckCloud TDuckCloud (tduck-platform) 5.1
Timeline
- 2025-09-16: disclosed: Vulnerability details and PoC published on GitHub Gist
- 2025-09-16: advisory: CVE-2025-57631 published