CVE-2023-29492
Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
Summary dbcve.org
Novi Survey versions prior to 8.9.43676 contain a remote code execution flaw that allows remote attackers to execute arbitrary code on the server in the context of the application service account. The underlying weakness (e.g., injection, deserialization) is not detailed in the advisory, but the impact is full server-side code execution reachable by remote attackers. The advisory notes the issue does not grant access to stored survey or response data, indicating the compromise is scoped to the application/service account context rather than the underlying data store.
Mitigation
Upgrade Novi Survey to version 8.9.43676 or later as a priority, given the critical CVSS 9.8 score and unauthenticated remote exploitability. Following the patch, review the service account's privileges to enforce least-privilege and audit the host for indicators of prior compromise.