Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-46485

EPSS 2.00% · P84
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-46485

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Data Illusion Survey Software Solutions NGSurvey 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ngSurvey是ngSurvey公司的一个数据错觉调查软件解决方案。 Data Illusion Survey Software Solutions NGSurvey v2.4.28及之前版本存在安全漏洞,该漏洞源于如果提交的调查包含 Text Field, Comment Field or Contact Details字段,容易受到拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2022-46485

#POC DescriptionSource LinkShenlong Link
1An issue in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to cause a Denial of Service (DoS) via a crafted survey.https://github.com/WodenSec/CVE-2022-46485POC Details
2An issue in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to cause a Denial of Service (DoS) via a crafted survey.https://github.com/NevaSec/CVE-2022-46485POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-46485

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-08-02 · 9 CVEs total

CVE-2023-38330Oxid Esales OXID eShop 代码问题漏洞
CVE-2022-46484Data Illusion Survey Software Solutions NGSurvey 信息泄露漏洞
CVE-2023-33383Shelly 4PM Pro 缓冲区错误漏洞
CVE-2023-33257Verint Engagement Management 跨站脚本漏洞
CVE-2023-26316Xiaomi cloud service Application 跨站脚本漏洞
CVE-2023-36081GatesAIr Flexiva FM Transmitter 跨站脚本漏洞
CVE-2023-39114ngiflib 安全漏洞
CVE-2023-39113ngiflib 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2022-46485

No comments yet


Leave a comment