Stored XSS Vulnerability in DWSurvey by WKeyuan
CVE-2019-14747

6.1MEDIUM

Key Information:

Vendor

Diaowen

Status
Vendor
CVE Published:
7 August 2019

What is CVE-2019-14747?

DWSurvey, a survey management tool, is vulnerable to stored Cross-Site Scripting (XSS) due to improper handling of the 'surveyName' parameter in the design copy survey action. An attacker can exploit this vulnerability by injecting malicious scripts, which are then stored and executed in the context of users accessing the survey design interface. This flaw could lead to unauthorized data access or manipulation, posing a significant security risk to users and their data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.