CVE-2019-25263

MEDIUM

Zendesk App SweetHawk Survey 1.6 - Stored Cross-Site Scripting via Support Ticket Submission

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25263. PoCs published by MTK.

AI-analyzed exploit summary This is a technical writeup describing a persistent XSS vulnerability in Zendesk App SweetHawk Survey up to version 1.6. The vulnerability allows attackers to inject malicious scripts into support tickets, which are then executed when users access the survey page.

Description

Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users.

Exploits (1)

exploitdb WRITEUP
by MTK · textwebappsjava
https://www.exploit-db.com/exploits/47781

This is a technical writeup describing a persistent XSS vulnerability in Zendesk App SweetHawk Survey up to version 1.6. The vulnerability allows attackers to inject malicious scripts into support tickets, which are then executed when users access the survey page.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Zendesk App SweetHawk Survey v1.6
Auth required
Prerequisites: Access to create or modify a support ticket in Zendesk
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47781
Various Sources product
https://sweethawk.co/zendesk/survey-app

Scores

CVSS v3 6.4
EPSS 0.0024
EPSS Percentile 14.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Sweethawk/Zendesk App SweetHawk Survey 1.6
Published Feb 03, 2026
Tracked Since Feb 18, 2026