Executive brief
DWSurvey is a web-based survey and form creation platform. A vulnerability in the survey design endpoint allows attackers to bypass authorization checks and access or modify surveys without proper authentication, potentially exposing sensitive survey data or enabling unauthorized modifications to surveys.
Technical details
An authorization bypass vulnerability exists in the DwDeisgnSurveyController.devSurvey function within the /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do endpoint. The vulnerability allows attackers to bypass access controls through a likely IDOR (Insecure Direct Object Reference) mechanism, enabling unauthorized remote access to survey data and functionality. The attack requires network connectivity but no prior authentication. Exploitation permits an attacker to view, modify, or delete surveys belonging to other users. The vendor did not respond to early disclosure notifications, and the exploit details have been publicly released.
Affected products
- diaowen DWSurvey up to 6.14.0
Timeline
- 2026-08-04: disclosed