PatchSiren cyber security CVE debrief
CVE-2025-15479 Data Illusion Zumbrunn CVE debrief
A stored cross-site scripting (XSS) vulnerability exists in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4. Authenticated remote users with survey creation or edit privileges can execute arbitrary JavaScript in other users' browsers via crafted survey content. This vulnerability affects survey content and administration functionality on Windows and Linux servers. System administrators and security teams should assess exposure and prioritize remediation based on the potential impact of unauthorized actions and data theft.
- Vendor
- Data Illusion Zumbrunn
- Product
- NGSurvey
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
System administrators and security teams responsible for managing and securing NGSurvey Enterprise Edition installations should assess exposure and prioritize remediation. This includes reviewing system configurations, user privileges, and survey content for potential vulnerabilities. Security teams should also monitor for suspicious activity and implement additional security measures to detect and prevent XSS attacks.
Why it matters
This stored XSS vulnerability in NGSurvey Enterprise Edition 3.6.4 allows authenticated remote users to execute arbitrary JavaScript in other users' browsers, potentially leading to unauthorized actions and data theft. System administrators and security teams should assess exposure and prioritize remediation.
- Execution of arbitrary JavaScript in users' browsers
- Potential theft of session information
- Unauthorized actions on behalf of other users
Technical summary
The vulnerability exists in the survey content and administration functionality of Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4. Authenticated remote users with survey creation or edit privileges can execute arbitrary JavaScript in other users' browsers via crafted survey content that is rendered without proper output encoding. This issue allows for potential theft of session information and unauthorized actions on behalf of other users. The vulnerability is classified as CWE-79, Stored Cross-Site Scripting.
Defensive priority
Medium-priority defensive actions are recommended to address this vulnerability.
Recommended defensive actions
- Review and update NGSurvey Enterprise Edition to version 3.6.17 or later.
- Restrict survey creation and edit privileges to trusted users.
- Implement additional security measures to detect and prevent XSS attacks.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability. However, the scope of affected versions and platforms requires further verification. The vulnerability is confirmed in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4, and additional details may be needed to assess exposure in other versions or configurations. Defenders should verify the presence of affected product deployments in managed environments and review official advisories for specific guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15479 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15479
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15479 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15479
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cds.thalesgroup.com/en/tcs-cert/CVE-2025-15479
64c5ae8f-7972-4697-86a0-7ada793ac795 - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://docs.ngsurvey.com/installation-setup/change-log
64c5ae8f-7972-4697-86a0-7ada793ac795 - Release Notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.