CVE-2023-35764

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ays-pro:survey_maker:*:*:*:*:*:wordpress:*:*

History

10 Oct 2025, 17:18

Type Values Removed Values Added
CPE cpe:2.3:a:ays-pro:survey_maker:*:*:*:*:*:wordpress:*:*
First Time Ays-pro
Ays-pro survey Maker
References () https://jvn.jp/en/jp/JVN51098626/ - () https://jvn.jp/en/jp/JVN51098626/ - Third Party Advisory
References () https://wordpress.org/plugins/survey-maker/ - () https://wordpress.org/plugins/survey-maker/ - Product

21 Nov 2024, 08:08

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN51098626/ - () https://jvn.jp/en/jp/JVN51098626/ -
References () https://wordpress.org/plugins/survey-maker/ - () https://wordpress.org/plugins/survey-maker/ -

12 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-345

03 Apr 2024, 12:38

Type Values Removed Values Added
Summary
  • (es) El problema de verificación insuficiente de la autenticidad de los datos en Survey Maker antes de la versión 3.6.4 permite que un atacante remoto no autenticado falsifique una dirección IP al publicar.

03 Apr 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 08:15

Updated : 2025-10-10 17:18


NVD link : CVE-2023-35764

Mitre link : CVE-2023-35764

CVE.ORG link : CVE-2023-35764


JSON object : View

Products Affected

ays-pro

  • survey_maker
CWE
CWE-345

Insufficient Verification of Data Authenticity