Untriaged
Permalink
CVE-2020-36993
6.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.
References
- ExploitDB-48762 exploit
- LimeSurvey Official Website product
- LimeSurvey Patch Commit issue-tracking patch
- VulnCheck Advisory: LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting third-party-advisory
- LimeSurvey Official Website product
- LimeSurvey Patch Commit issue-tracking patch
- VulnCheck Advisory: LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting third-party-advisory
- ExploitDB-48762 exploit
- ExploitDB-48762 exploit
- LimeSurvey Official Website product
- LimeSurvey Patch Commit issue-tracking patch
- VulnCheck Advisory: LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting third-party-advisory
Affected products
LimeSurvey
- =<4.3.10
Matching in nixpkgs
pkgs.limesurvey
Open source survey application
-
nixos-unstable 6.15.14+250924
- nixpkgs-unstable 6.15.14+250924
- nixos-unstable-small 6.15.14+250924
Package maintainers
-
@offlinehacker Jaka Hudoklin <jaka@x-truder.net>