CVE-2021-41123 is a medium-severity information disclosure vulnerability affecting Survey Solutions, a survey management and data collection system. The vulnerability exposes an unauthenticated /metrics endpoint in the Headquarters application, revealing aggregate counters such as interview and assignment counts. While no sensitive survey answers are exposed, this could still provide an attacker with insights into system activity. The CVSS score of 5.3 indicates a low-complexity attack that can be executed remotely without user interaction, resulting in a low impact on confidentiality and no impact on integrity or availability. The EPSS score and FAUCET Risk Score suggest a low likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.09.1CPE matchmatch criteria | cpe:2.3:a:mysurvey:survey_solutions:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.