View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
17444 | Bug reports | Response browsing | public | 2021-07-15 13:55 | 2022-05-19 20:44 |
Reporter | galads | Assigned To | |||
Priority | normal | Severity | partial_block | ||
Status | confirmed | Resolution | open | ||
Product Version | 3.25.20 | ||||
Summary | 17444: Survey in 'all in one' mode creates response entry as soon as the survey is visited | ||||
Description | When a participant "saves and resumes later", a new entry is entered in the participant's table. In the "Lime_save_control" a new entry is entered as expected. Then the user is able to finish the loaded survey but the new empty entry is still available in the response table. Attack possible in all in one survey when save and resume functionality is used | ||||
Steps To Reproduce |
2 entries in the response table. One empty response from the same participant. | ||||
Additional Information | Survey details: (All in one) | ||||
Tags | No tags attached. | ||||
Bug heat | 8 | ||||
Complete LimeSurvey version number (& build) | 3.27.5 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | no relevant | ||||
Server OS (if known) | |||||
Webserver software & version (if known) | |||||
PHP Version | not relevant | ||||
I think there are a lack of detail here : i can reproduce on a group by group survey. Survey all in one page ? Hide welcome page ? Because we can npot do
Save and resume later didn't appear on welcome page. Else i try
|
|
Well I did not include all steps I added more information: It happens for "all in one" surveys |
|
I think the important part are "All in one" ;) |
|
There doesn't seem to be an issue with save and resume. 1) Created survey, with "Create example question group and question?" = "On" However, if you try to execute the survey with the normal link (instead of the link from the "saved" email), an empty response is saved. I think this is a colateral damage. |
|
What I see here is a secruity issue. |
|
OK ! Maybe report this one as new issue unrelated to save part ? |
|
This happens when the survey link is used and not the link sent to the email. I agree with you that this is a security issue (attack with a lot of empty responses). I will change it to "attack possible in all in one survey when save and resume functionality is used" |
|
It is a general problem of the way we save the response in all-in-one mode. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2021-07-15 13:55 | galads | New Issue | |
2021-07-15 13:55 | galads | Status | new => assigned |
2021-07-15 13:55 | galads | Assigned To | => galads |
2021-07-15 13:56 | galads | Status | assigned => confirmed |
2021-07-15 14:13 | DenisChenu | Note Added: 65454 | |
2021-07-15 14:38 | galads | Description Updated | |
2021-07-15 14:38 | galads | Steps to Reproduce Updated | |
2021-07-15 14:38 | galads | Additional Information Updated | |
2021-07-15 15:01 | galads | Note Added: 65457 | |
2021-07-15 15:04 | DenisChenu | Note Added: 65458 | |
2021-07-16 16:06 | galads | Sync to Zoho Project | => |Yes| |
2021-07-19 17:01 | galads | Assigned To | galads => gabrieljenik |
2021-07-19 17:01 | galads | Priority | none => high |
2021-07-19 17:01 | galads | Reproducibility | have not tried => always |
2021-07-19 17:01 | galads | Status | confirmed => assigned |
2021-07-19 17:01 | galads | Sync to Zoho Project | Yes => |Yes| |
2021-07-28 15:00 | gabrieljenik | Note Added: 65679 | |
2021-07-28 15:01 | gabrieljenik | Note Added: 65681 | |
2021-07-28 15:03 | DenisChenu | Note Added: 65683 | |
2021-07-29 17:16 | galads | Note Added: 65751 | |
2021-07-29 17:23 | galads | Summary | "save and resum later", creates a new empty entry in the response table. => "save and resum later", creates a new empty entry in the response table for "all in one" (attack possible) |
2021-07-29 17:23 | galads | Description Updated | |
2021-07-29 17:23 | galads | Sync to Zoho Project | Yes => |Yes| |
2021-08-16 09:35 | c_schmitz | Note Added: 65991 | |
2021-08-16 09:35 | c_schmitz | Bug heat | 6 => 8 |
2021-08-16 09:36 | c_schmitz | Summary | "save and resum later", creates a new empty entry in the response table for "all in one" (attack possible) => Survey in 'all in one' mode creates response entry as soon as the survey is visited |
2021-08-16 09:36 | c_schmitz | Sync to Zoho Project | Yes => |Yes| |
2021-08-16 09:37 | c_schmitz | Sync to Zoho Project | Yes => |Yes| |
2022-05-19 20:44 | c_schmitz | Priority | high => normal |
2022-05-19 20:44 | c_schmitz | Assigned To | gabrieljenik => |
2022-05-19 20:44 | c_schmitz | Status | assigned => confirmed |