CVE-2025-13829

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name
CVSS

No CVSS.

Configurations

No configuration.

History

01 Dec 2025, 17:15

Type Values Removed Values Added
Summary (en) Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurveyallows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name (en) Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt * User IP * Email * Full Name

01 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 16:15

Updated : 2025-12-02 17:16


NVD link : CVE-2025-13829

Mitre link : CVE-2025-13829

CVE.ORG link : CVE-2025-13829


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization