Gallup Addresses XSS Bugs in Website
ID: 0118633a-f272-5a99-a889-ee1c4af8161e
STIX ID: report--0118633a-f272-5a99-a889-ee1c4af8161e
Feed Name: Dark Reading
Date Published: 2024-09-10
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Dark Reading reports that Checkmarx disclosed two cross-site scripting (XSS) vulnerabilities on Gallup.com — a reflected XSS (CVSS 6.5) and a DOM-based XSS (CVSS 5.4). Gallup patched the site and researchers recommended proper output encoding and tightening the Content Security Policy; the article clarifies the bugs affected the public website only and did not put internal data at risk, and notes that parts of the original Checkmarx research are disputed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
