CRITICAL
CVE-2021-27852
CVSS
9.8
KEV
Description
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
Summary dbcve.org
A deserialization vulnerability exists in CheckboxWeb.dll of Checkbox Survey versions prior to version 7. The vulnerability allows unauthenticated remote attackers to execute arbitrary code through unsafe deserialization of untrusted data.
Mitigation
Upgrade Checkbox Survey to version 7 or later to remediate this critical deserialization vulnerability.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
30.26%
Probability of exploitation in next 30 days
98.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.