CVE-2026-100303 - TDuck survey form through 6.0 Missing Authorization in Form Theme Management Endpoints
CVE ID :CVE-2026-100303
Published : Sept. 25, 2026, 6:47 p.m. | 23 minutes ago
Description :TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 25, 2026, 6:47 p.m. | 23 minutes ago
Description :TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...