CVE-2023-29492

novisurvey novi_survey

Published 11 Apr 2023 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 13 Apr 2023, with a remediation deadline of 4 May 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

References