Data Illusion Zumbrunn ngSurvey Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Data Illusion Zumbrunn ngSurvey Enterprise Edition versions 3.6.4, on all supported platforms including Windows and Linux servers. This vulnerability allows authenticated remote users with survey creation or editing privileges to inject arbitrary JavaScript into survey content. The crafted content is rendered without proper output encoding, enabling the execution of the injected script in the browsers of other users. This could lead to the theft of session information and unauthorized actions performed on behalf of the affected users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the survey, potentially leading to session hijacking and unauthorized actions.

Added: Jan 7, 2026, 5:46 PM
Updated: Jan 7, 2026, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
5.2
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.