VDB
Sign up
MEDIUM6.1

GHSA-xgj4-2hrf-j4xg

Cross-site scripting in Survey Creator

Quick fix

GHSA-xgj4-2hrf-j4xg — survey-creator: upgrade to the fixed version with the command below.

npm install survey-creator@1.9.133

Details

Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/survey-creator
Introduced in: 0Fixed in: 1.9.133
Fixnpm install survey-creator@1.9.133

References