Show filters
222 Total Results
Displaying 151-160 of 222
Sort by:
Attacker Value
Unknown
CVE-2019-16186
Disclosure Date: September 09, 2019 (last updated November 27, 2024)
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
0
Attacker Value
Unknown
CVE-2019-16175
Disclosure Date: September 09, 2019 (last updated November 27, 2024)
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
0
Attacker Value
Unknown
CVE-2019-16172
Disclosure Date: September 09, 2019 (last updated November 27, 2024)
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
0
Attacker Value
Unknown
CVE-2019-16173
Disclosure Date: September 09, 2019 (last updated November 27, 2024)
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
0
Attacker Value
Unknown
CVE-2019-15640
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
0
Attacker Value
Unknown
CVE-2019-15095
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
0
Attacker Value
Unknown
CVE-2019-14747
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
0
Attacker Value
Unknown
CVE-2019-17599
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
0
Attacker Value
Unknown
CVE-2019-9960
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
0
Attacker Value
Unknown
CVE-2019-9575
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
0