← לוח פגיעויות

CVE-2021-27852

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Checkbox Survey Deserialization of Untrusted Data Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.

תיאור (מקור, אנגלית)

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
32% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-502

מוצרים מושפעים

checkbox: survey

קישורים