What the vulnerability does
01Description
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
Explanation of Vulnerability in Simple Terms
Survey Maker through version 5.2.3.3 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into survey pages. When a victim visits a compromised survey, the attacker's code runs in their browser with access to their session and data. The vulnerability requires user interaction but can affect multiple users across the site.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers, stealing session cookies or redirecting them to phishing sites.
Potential impact on your site
Survey responses and user data may be compromised; site reputation damaged if used for phishing or malware distribution.
Conditions required to exploit
Attacker must craft a malicious survey URL or content; victim must visit the affected survey page.
Key dates
External resources
Related vulnerabilities