Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms ( on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding.
History

Wed, 07 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 07 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
Description Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms ( on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding.
Title NGSurvey Enterprise 3.6.4 incorrect authorization exposes other users’ API keys and personal data
First Time appeared Data Illusion Zumbrunn
Data Illusion Zumbrunn ngsurvey
CPEs cpe:2.3:a:data_illusion_zumbrunn:ngsurvey:*:*:linux:*:*:*:*:*
cpe:2.3:a:data_illusion_zumbrunn:ngsurvey:*:*:windows:*:*:*:*:*
Vendors & Products Data Illusion Zumbrunn
Data Illusion Zumbrunn ngsurvey
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TCS-CERT

Published:

Updated: 2026-01-07T15:03:22.729Z

Reserved: 2026-01-07T13:10:13.147Z

Link: CVE-2025-15479

cve-icon Vulnrichment

Updated: 2026-01-07T14:10:33.597Z

cve-icon NVD

Status : Received

Published: 2026-01-07T14:15:53.280

Modified: 2026-01-07T15:15:44.630

Link: CVE-2025-15479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.