PT-2026-1656 · Data Illusion · Zumbrunn Ngsurvey Enterprise Edition
Thomas Clair
·
Published
2026-01-07
·
Updated
2026-01-29
·
CVE-2025-15479
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Data Illusion Zumbrunn NGSurvey Enterprise Edition version 3.6.4
Description
The software contains a stored cross-site scripting issue. This affects the survey content and administration functionality, allowing authenticated remote users with survey creation or edit privileges to execute arbitrary JavaScript in other users’ browsers. This could lead to session information theft and unauthorized actions. The issue occurs because crafted survey content is rendered without proper output encoding.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zumbrunn Ngsurvey Enterprise Edition