A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization | |
| First Time appeared |
Diaowen
Diaowen dwsurvey |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:diaowen:dwsurvey:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Diaowen
Diaowen dwsurvey |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-04T03:00:08.926Z
Reserved: 2026-08-03T17:50:34.988Z
Link: CVE-2026-18722
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T09:30:06Z