TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses.
References
Configurations
No configuration.
History
16 Sep 2026, 17:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 17:18
Updated : 2026-09-16 17:18
NVD link : CVE-2026-92602
Mitre link : CVE-2026-92602
CVE.ORG link : CVE-2026-92602
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
