PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15479 Data Illusion Zumbrunn CVE debrief

A stored cross-site scripting (XSS) vulnerability exists in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4. Authenticated remote users with survey creation or edit privileges can execute arbitrary JavaScript in other users' browsers via crafted survey content. This vulnerability affects survey content and administration functionality on Windows and Linux servers. System administrators and security teams should assess exposure and prioritize remediation based on the potential impact of unauthorized actions and data theft.

Vendor
Data Illusion Zumbrunn
Product
NGSurvey
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

System administrators and security teams responsible for managing and securing NGSurvey Enterprise Edition installations should assess exposure and prioritize remediation. This includes reviewing system configurations, user privileges, and survey content for potential vulnerabilities. Security teams should also monitor for suspicious activity and implement additional security measures to detect and prevent XSS attacks.

Why it matters

This stored XSS vulnerability in NGSurvey Enterprise Edition 3.6.4 allows authenticated remote users to execute arbitrary JavaScript in other users' browsers, potentially leading to unauthorized actions and data theft. System administrators and security teams should assess exposure and prioritize remediation.

  • Execution of arbitrary JavaScript in users' browsers
  • Potential theft of session information
  • Unauthorized actions on behalf of other users

Technical summary

The vulnerability exists in the survey content and administration functionality of Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4. Authenticated remote users with survey creation or edit privileges can execute arbitrary JavaScript in other users' browsers via crafted survey content that is rendered without proper output encoding. This issue allows for potential theft of session information and unauthorized actions on behalf of other users. The vulnerability is classified as CWE-79, Stored Cross-Site Scripting.

Defensive priority

Medium-priority defensive actions are recommended to address this vulnerability.

Recommended defensive actions

  • Review and update NGSurvey Enterprise Edition to version 3.6.17 or later.
  • Restrict survey creation and edit privileges to trusted users.
  • Implement additional security measures to detect and prevent XSS attacks.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability. However, the scope of affected versions and platforms requires further verification. The vulnerability is confirmed in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4, and additional details may be needed to assess exposure in other versions or configurations. Defenders should verify the presence of affected product deployments in managed environments and review official advisories for specific guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15479 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15479

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15479 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15479

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cds.thalesgroup.com/en/tcs-cert/CVE-2025-15479

    64c5ae8f-7972-4697-86a0-7ada793ac795 - Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://docs.ngsurvey.com/installation-setup/change-log

    64c5ae8f-7972-4697-86a0-7ada793ac795 - Release Notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.