This issue was first reported by:

and later via pull request by:

We thank both of you!

There is a XSS vulnerability in the Survey module, which can used to extract information via JavaScript.
The issue is fixed in the current release 6.0.21 which is available via the package manager or on our
downloads server.