What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Explanation of Vulnerability in Simple Terms
SureFeedback Client Site versions up to 1.2.12 lack proper authorization checks, allowing unauthenticated attackers to read sensitive data through network requests. The vulnerability requires no user interaction and can be exploited remotely. No integrity or availability impact is present, but confidential information may be exposed.
What an attacker can do
Read sensitive data without authentication by sending network requests to the application.
Potential impact on your site
Confidential information stored in SureFeedback Client Site may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities