Show filters
68 Total Results
Displaying 41-50 of 68
Sort by:
Attacker Value
Unknown
CVE-2019-15640
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
0
Attacker Value
Unknown
CVE-2019-9960
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
0
Attacker Value
Unknown
CVE-2017-18358
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.
0
Attacker Value
Unknown
CVE-2018-20322
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
0
Attacker Value
Unknown
CVE-2018-17003
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
0
Attacker Value
Unknown
CVE-2018-17057
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
0
Attacker Value
Unknown
CVE-2018-1000658
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.
0
Attacker Value
Unknown
CVE-2018-1000659
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip file to get remote code execution. This vulnerability appears to have been fixed in after commit 72a02ebaaf95a80e26127ee7ee2b123cccce05a7 / version 3.14.4.
0
Attacker Value
Unknown
CVE-2018-16397
Disclosure Date: September 03, 2018 (last updated November 27, 2024)
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
0
Attacker Value
Unknown
CVE-2018-1000513
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS code execution against LimeSurvey admins. This vulnerability appears to have been fixed in 3.6.x.
0