Show filters
66 Total Results
Displaying 41-50 of 66
Sort by:
Attacker Value
Unknown
CVE-2017-18358
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.
0
Attacker Value
Unknown
CVE-2018-20322
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
0
Attacker Value
Unknown
CVE-2018-17003
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
0
Attacker Value
Unknown
CVE-2018-17057
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
0
Attacker Value
Unknown
CVE-2018-1000658
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.
0
Attacker Value
Unknown
CVE-2018-1000659
Disclosure Date: September 06, 2018 (last updated November 27, 2024)
LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip file to get remote code execution. This vulnerability appears to have been fixed in after commit 72a02ebaaf95a80e26127ee7ee2b123cccce05a7 / version 3.14.4.
0
Attacker Value
Unknown
CVE-2018-16397
Disclosure Date: September 03, 2018 (last updated November 27, 2024)
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
0
Attacker Value
Unknown
CVE-2018-1000513
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS code execution against LimeSurvey admins. This vulnerability appears to have been fixed in 3.6.x.
0
Attacker Value
Unknown
CVE-2018-1000514
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes. This vulnerability appears to have been fixed in 3.6.x.
0
Attacker Value
Unknown
CVE-2018-7556
Disclosure Date: February 28, 2018 (last updated November 26, 2024)
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
0