CVE-2021-27852Checkbox Survey Deserialization of Untrusted Data Vulnerability

PUBLISHEDvulnerability record
2022-04-11 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-27852
Project:
Checkbox
Product:
Checkbox Survey
Date Added:
2022-04-11
Due Date:
2022-05-02
Last Updated:
June 21, 2025

Vulnerability Name

Checkbox Survey Deserialization of Untrusted Data Vulnerability

Description

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.

Additional Notes

Related Weaknesses