CRITICAL

CVE-2021-27852

Checkbox Survey 2021-05-27 CVSS v3.1
CVSS
9.8
KEV

Description

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

Summary dbcve.org

A deserialization vulnerability exists in CheckboxWeb.dll of Checkbox Survey versions prior to version 7. The vulnerability allows unauthenticated remote attackers to execute arbitrary code through unsafe deserialization of untrusted data.

Mitigation

Upgrade Checkbox Survey to version 7 or later to remediate this critical deserialization vulnerability.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

30.26%
Probability of exploitation in next 30 days
98.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE