CVE-2021-27852 is a critical deserialization of untrusted data vulnerability in Checkbox Survey versions prior to 7, allowing unauthenticated remote attackers to execute arbitrary code. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and significant media coverage, despite a lack of public exploit code in Metasploit, Nuclei, or ExploitDB. The high volume of community discussion further underscores its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7CPE match | cpe:2.3:a:checkbox:survey:*:*:*:*:*:*:*:* | ||
< 7.0CPE matchmatch criteria | cpe:2.3:a:checkbox:survey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.