Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms (
on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding.
Metrics
Affected Vendors & Products
References
History
Wed, 07 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Wed, 07 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms ( on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding. | |
| Title | NGSurvey Enterprise 3.6.4 incorrect authorization exposes other users’ API keys and personal data | |
| First Time appeared |
Data Illusion Zumbrunn
Data Illusion Zumbrunn ngsurvey |
|
| CPEs | cpe:2.3:a:data_illusion_zumbrunn:ngsurvey:*:*:linux:*:*:*:*:* cpe:2.3:a:data_illusion_zumbrunn:ngsurvey:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Data Illusion Zumbrunn
Data Illusion Zumbrunn ngsurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TCS-CERT
Published:
Updated: 2026-01-07T15:03:22.729Z
Reserved: 2026-01-07T13:10:13.147Z
Link: CVE-2025-15479
Updated: 2026-01-07T14:10:33.597Z
Status : Received
Published: 2026-01-07T14:15:53.280
Modified: 2026-01-07T15:15:44.630
Link: CVE-2025-15479
No data.
OpenCVE Enrichment
No data.