Show filters
68 Total Results
Displaying 1-10 of 68
Sort by:
Attacker Value
Unknown
CVE-2024-28710
Disclosure Date: October 07, 2024 (last updated October 16, 2024)
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
0
Attacker Value
Unknown
CVE-2024-28709
Disclosure Date: October 07, 2024 (last updated October 16, 2024)
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
0
Attacker Value
Unknown
CVE-2024-42903
Disclosure Date: September 03, 2024 (last updated September 13, 2024)
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
0
Attacker Value
Unknown
CVE-2024-7887
Disclosure Date: August 17, 2024 (last updated August 17, 2024)
A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-6933
Disclosure Date: July 21, 2024 (last updated July 21, 2024)
A vulnerability was found in LimeSurvey 6.5.14-240624. It has been rated as critical. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. The manipulation of the argument language leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-44796
Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
0
Attacker Value
Unknown
CVE-2022-48010
Disclosure Date: January 27, 2023 (last updated November 08, 2023)
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Welcome-message text fields. NOTE: the vendor indicates that this is not a vulnerability because the manipulation requires Superadministrator privileges, and Superadministrators are already allowed to customize surveys with JavaScript as they wish.
0
Attacker Value
Unknown
CVE-2022-48008
Disclosure Date: January 27, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-43279
Disclosure Date: November 15, 2022 (last updated May 15, 2024)
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
0
Attacker Value
Unknown
CVE-2022-29710
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
0