CVE-2023-35764: Medium severity survey maker vulnerability
Published Apr 3, 2024
·Updated
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
Affected Software
2 affected components
Survey Maker Survey Maker<3.6.4
ays-pro Survey Maker Wordpress<3.6.4
Event History
Apr 3, 2024
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability description for CVE-2023-35764?
CVE-2023-35764 is an insufficient verification of data authenticity issue in Survey Maker prior to version 3.6.4 that allows a remote unauthenticated attacker to spoof an IP address when posting.
2
What versions of Survey Maker are affected by CVE-2023-35764?
CVE-2023-35764 affects all versions of Survey Maker prior to 3.6.4.
3
What is the severity level of CVE-2023-35764?
The severity level of CVE-2023-35764 is considered significant due to the potential for remote spoofing attacks.
4
How do I mitigate the risks associated with CVE-2023-35764?
To mitigate the risks associated with CVE-2023-35764, it is recommended to upgrade Survey Maker to version 3.6.4 or later.
5
Can CVE-2023-35764 be exploited remotely?
Yes, CVE-2023-35764 can be exploited remotely by unauthenticated attackers.