Access denied error accessing my surveys | XM Community

Access denied error accessing my surveys

  • 14 December 2021
  • 3 replies
  • 329 views

Userlevel 5
Badge +13

Today a change happened within the Qualtrics Survey Platform that broke all of my surveys. If I try to access

https://unc.az1.qualtrics.com/jfe/form/SV_5BIjIAz4c6DR2Fo?ReturnURL=https%3A%2F%2Fsomedomain.edu%2Fqualtrics%2FSV_xyz%2Fget-response%3FQ_R%3DR_abc%26session%3D%24%7Be%3A%2F%2FField%2FSessionID%7D%26ONYEN%3D%24%7Be%3A%2F%2FField%2FONYEN%7D%26startDate%3D%24%7Bdate%3A%2F%2FOtherDate%2FY%252Fm%252Fd%2F-1%20day%7DT%24%7Bdate%3A%2F%2FCurrentTime%2FMS%7DZ%26endDate%3D%24%7Bdate%3A%2F%2FOtherDate%2FY%252Fm%252Fd%2F%2B1%20day%7DT%24%7Bdate%3A%2F%2FCurrentTime%2FMS%7DZ%26rid%3D%24%7Be%3A%2F%2FField%2FResponseID%7D%26sid%3D%24%7Be%3A%2F%2FField%2FSurveyID%7D
I receive an error saying:
Access Denied
You don't have permission to access "http://unc.az1.qualtrics.com/jfe/form/SV_5BIjIAz4c6DR2Fo?" on this server.
If I exclude the query string and simply access
https://unc.az1.qualtrics.com/jfe/form/SV_5BIjIAz4c6DR2Fo
then no error messages occur, so I know it is a problem with the Qualtrics query string parser. This is happening on all of my surveys. I use custom query strings in my distribution URLs heavily, so all of my applications using Qualtrics are out of commission and we are having to cancel appointments tomorrow due to outage. I submitted a help ticket (CS_0B5D010C87674519) and it was closed without any followup or response as to why it was closed. Some sort of resolution on this issue would be nice. - thank you


3 replies

Userlevel 2
Badge

I think youre parsing vulnerable string, Can you please check this query is from unique link or what?

Badge +1

w.patrick.gale - was there any resolution to this? We are facing the same challenge all of a sudden.

Userlevel 5
Badge +13

@HM1234 luckily Qualtrics must have updated their software shortly after I reported the incident because the issue has not resurfaced since December.

Leave a Reply