{"id":"CVE-2025-13829","title":"Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.\n\n\n\n Critical information retrieved: \n  *  APIKEY (1 year user Session)\n  *  RefreshTo…","summary":"Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.\n\n\n\n Critical information retrieved: \n  *  APIKEY (1 year user Session)\n  *  RefreshTo…","severity":"none","cwe":["CWE-863"],"published":"2025-12-01","updated":"2026-09-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13829","references":[{"url":"https://docs.ngsurvey.com/installation-setup/change-log#id-3.6.17-2025-05-28","label":"64c5ae8f-7972-4697-86a0-7ada793ac795"}],"tags":["nvd"],"epss":0.00303,"epssPercentile":0.2328,"ingestedAt":"2026-09-03T03:55:23.734Z","slug":"CVE-2025-13829","body":"## Overview\n\nIncorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.\n\n\n\n Critical information retrieved: \n  *  APIKEY (1 year user Session)\n  *  RefreshToken (10 minutes user Session)\n  *  Password hashed with bcrypt\n  *  User IP\n  *  Email\n  *  Full Name\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}