CVE-2022-29710
- EPSS 0.47%
- Veröffentlicht 25.05.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:59:35
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
- EPSS 68.26%
- Veröffentlicht 24.02.2022 15:15:24
- Zuletzt bearbeitet 20.02.2025 03:15:11
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally ...
CVE-2018-10228
- EPSS 0.23%
- Veröffentlicht 14.12.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 03:41:03
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavech...
CVE-2021-42112
- EPSS 0.58%
- Veröffentlicht 08.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:17
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
CVE-2020-22607
- EPSS 0.22%
- Veröffentlicht 28.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:13:18
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
CVE-2020-23710
- EPSS 0.28%
- Veröffentlicht 28.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:14:01
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
CVE-2019-25019
- EPSS 0.44%
- Veröffentlicht 14.02.2021 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:39:45
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
CVE-2020-25799
- EPSS 0.26%
- Veröffentlicht 31.12.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:48
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.
CVE-2020-25797
- EPSS 0.26%
- Veröffentlicht 31.12.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:48
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the brows...
CVE-2020-25798
- EPSS 0.26%
- Veröffentlicht 17.11.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:48
A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes o...