CVE-2019-25263

MEDIUM

Zendesk SweetHawk Survey 1.6 - XSS

Title source: llm
STIX 2.1

Description

Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users.

Exploits (1)

exploitdb WRITEUP
by MTK · textwebappsjava
https://www.exploit-db.com/exploits/47781

Scores

CVSS v3 6.4
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Sweethawk/Zendesk App SweetHawk Survey 1.6
Published Feb 03, 2026
Tracked Since Feb 18, 2026