CVE-2025-63248: High severity DWSurvey DWSurvey vulnerability
Published Nov 5, 2025
·Updated
DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletion of other questionnaires.
Affected Software
2 affected components
DWSurvey DWSurvey
Diaowen Dwsurvey=6.14.0
Event History
Nov 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63248?
CVE-2025-63248 has a high severity due to its impact on the integrity of questionnaire data.
2
How do I fix CVE-2025-63248?
To fix CVE-2025-63248, implement proper access control checks before allowing deletion of questionnaires to prevent unauthorized deletions.
3
Who is affected by CVE-2025-63248?
Users of DWSurvey version 6.14.0 are affected by CVE-2025-63248.
4
What type of vulnerability is CVE-2025-63248?
CVE-2025-63248 is classified as an Incorrect Access Control vulnerability.
5
What can happen if CVE-2025-63248 is exploited?
If exploited, CVE-2025-63248 can allow an attacker to delete any questionnaire by manipulating the questionnaire ID.