Intel

AIKIDO-2024-10187

survey-angular-ui is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

30

Low Risk

This Affects:

jssurvey-angular-ui
1.9.69 - 1.11.6
Fixed in 1.11.7

TL;DR

Affected versions of the package are vulnerable to a Cross-site Scripting (XSS) vulnerability, allowing an attacker to assign a script (e.g., javascript:alert('XXX')) to the survey.navigateToUrl property.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

survey-angular-ui is vulnerable to Cross-site Scripting (XSS) in versions 1.9.69 - 1.11.6.

How to fix this

Upgrade the survey-angular-ui library to the patch version.