Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/surveyjs/survey-creator/issues/5285 | Exploit Issue Tracking |
https://github.com/surveyjs/survey-creator/issues/5285 | Exploit Issue Tracking |
https://packetstormsecurity.com/2403-exploits/surveyjssurveycreator19132-xss.txt | Broken Link |
https://packetstormsecurity.com/2403-exploits/surveyjssurveycreator19132-xss.txt | Broken Link |
Configurations
History
17 Jun 2025, 14:05
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:devsoftbaltic:survey-creator:*:*:*:*:*:*:*:* | |
First Time |
Devsoftbaltic survey-creator
|
17 Jun 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Devsoftbaltic survey Creator
Devsoftbaltic |
|
CPE | cpe:2.3:a:devsoftbaltic:survey_creator:*:*:*:*:*:*:*:* | |
References | () https://github.com/surveyjs/survey-creator/issues/5285 - Exploit, Issue Tracking | |
References | () https://packetstormsecurity.com/2403-exploits/surveyjssurveycreator19132-xss.txt - Broken Link |
21 Mar 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-21 04:15
Updated : 2025-06-17 14:05
NVD link : CVE-2024-28635
Mitre link : CVE-2024-28635
JSON object : View
Products Affected
devsoftbaltic
- survey-creator
CWE
No CWE.