Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16172

Опубликовано: 09 сент. 2019
Источник: debian

Описание

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
limesurveyitppackage

Связанные уязвимости

CVSS3: 5.4
nvd
больше 6 лет назад

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

CVSS3: 5.4
github
больше 3 лет назад

Cross-site Scripting in LimeSurvey