Executive brief
SurveyJS Survey Creator is a tool used by developers to build and customize web-based surveys. A security flaw allows attackers to inject malicious scripts into survey forms via the title field. If an unsuspecting user or administrator views the affected form, the attacker could steal sensitive session information or perform unauthorized actions on their behalf.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in SurveyJS Survey Creator versions 1.9.132 and earlier. The vulnerability is rooted in the improper neutralization of user-supplied input within the 'title' parameter of a form. An unauthenticated remote attacker can exploit this by injecting a malicious script into the title field. When a victim views the crafted form, the script executes in the context of the victim's browser session. This can lead to the disclosure of sensitive information, such as session cookies, or the execution of arbitrary actions. The issue is addressed in version 1.9.133.
Affected products
- SurveyJS survey-creator <= 1.9.132
Timeline
- 2024-03-21: disclosed
- 2024-03-21: advisory
References
- https://api.github.com/users/TheeCryptoChad
- https://github.com/TheeCryptoChad
- https://api.github.com/users/TheeCryptoChad/gists%7B/gist_id%7D
- https://api.github.com/users/TheeCryptoChad/repos
- https://avatars.githubusercontent.com/u/54559164?v=4
- https://api.github.com/users/TheeCryptoChad/events%7B/privacy%7D