8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y
Description
Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.
Critical information retrieved:
* APIKEY (1 year user Session)
* RefreshToken (10 minutes user Session)
* Password hashed with bcrypt
* User IP
* Email
* Full Name
Critical information retrieved:
* APIKEY (1 year user Session)
* RefreshToken (10 minutes user Session)
* Password hashed with bcrypt
* User IP
* Full Name
AI Analysis
Incorrect Authorization vulnerability allowing access to private user information
Basic Information
ID
CVE-2025-13829
Source
TCS-CERT
Published
Dec 1, 2025 at 15:47
Modified
Dec 1, 2025 at 16:16
Affected Product
Vendor
Data Illusion Zumbrunn
Product
NGSurvey
Affected Versions
Data Illusion Zumbrunn NGSurvey 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Data Illusion Zumbrunn
Product
NGSurvey