Limesurvey

Limesurvey

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.36%
  • Veröffentlicht 09.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:11

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

  • EPSS 0.24%
  • Veröffentlicht 26.08.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:10

Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.

  • EPSS 70.08%
  • Veröffentlicht 24.03.2019 01:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:40

The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 15.01.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:55

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

  • EPSS 0.41%
  • Veröffentlicht 21.12.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:13

LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.

  • EPSS 0.21%
  • Veröffentlicht 21.09.2018 17:29:06
  • Zuletzt bearbeitet 21.11.2024 03:53:40

In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.

Exploit
  • EPSS 59.39%
  • Veröffentlicht 14.09.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:47

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

  • EPSS 2.16%
  • Veröffentlicht 06.09.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:20

LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exp...

  • EPSS 0.72%
  • Veröffentlicht 06.09.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:20

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive...

  • EPSS 0.37%
  • Veröffentlicht 03.09.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:40

In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,