D Soft Research · Dwsurvey · CVE-2019-15095
**Name of the Vulnerable Software and Affected Versions**
DWSurvey versions prior to 2019-07-22
**Description**
The issue is related to reflected XSS, which occurs via the `surveyId` parameter in the "design/qu-multi-fillblank!answers.action" endpoint. This allows for potential exploitation.
**Recommendations**
For versions prior to 2019-07-22, consider restricting access to the "design/qu-multi-fillblank!answers.action" endpoint until a fix is available, and avoid using the `surveyId` parameter in this endpoint to minimize the risk of exploitation.