Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 npm

Cross-site scripting in Survey Creator

GHSA-xgj4-2hrf-j4xg · CVE-2024-28635

Published · Modified

Description

Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.

Ready to move

Start Securing

Free, no credit card | First findings in minutes