CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-15479: ngsurvey before 3.6.17 (exclusive); +1 more affected products

CVE-2025-15479. CVSS 3.1 base score 5.4 (MEDIUM, NVD). EPSS 0.00201 (percentile 0.08991), scored 2026-10-05.

Affected technology

ngsurvey · before 3.6.17 (exclusive)
ngsurvey

NGSurvey · 3.6.4 to before 3.6.17; status changes: 3.6.17 — unaffected
Data Illusion Zumbrunn

Component: user profile management functionality

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · Passive user interaction

What an attacker can do

Authenticated remote users with survey creation or edit privileges can execute arbitrary JavaScript in other users’ browsers, steal session information and perform unauthorized actions on their behalf via crafted survey content that is rendered without proper output encoding. Source advisory’s CVSS 4.0 assessment (base score 5.1/10) rates confidentiality, integrity and availability impact as none.

Published

CWE
CWE-79
CCR priority
21.7 /100 (P4)
CVSS 3.1
5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N · NVD
EPSS
0.00201 · percentile 0.09048 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-15479.html