Skip to content

Cross-site scripting in Survey Creator

Moderate severity GitHub Reviewed Published Mar 21, 2024 to the GitHub Advisory Database • Updated Mar 21, 2024

Package

npm survey-creator (npm)

Affected versions

< 1.9.133

Patched versions

1.9.133

Description

Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.

References

Published by the National Vulnerability Database Mar 21, 2024
Published to the GitHub Advisory Database Mar 21, 2024
Reviewed Mar 21, 2024
Last updated Mar 21, 2024

Severity

Moderate

Weaknesses

CVE ID

CVE-2024-28635

GHSA ID

GHSA-xgj4-2hrf-j4xg
Checking history
See something to contribute? Suggest improvements for this vulnerability.