CVE 5.1 MEDIUM

NGSurvey Enterprise 3.6.4 incorrect authorization exposes other users’ API keys and personal data_CVE-2025-15479

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms (

on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding.

Basic Information

ID CVE-2025-15479
Source TCS-CERT
Published Jan 7, 2026 at 13:23
Modified Jan 7, 2026 at 15:03

Affected Product

Vendor Data Illusion Zumbrunn
Product NGSurvey
Version 3.6.4
Affected Versions Data Illusion Zumbrunn NGSurvey 3.6.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.