Описание
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Patch
- ExploitMailing ListThird Party Advisory
- Broken Link
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Patch
- ExploitMailing ListThird Party Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 3.17.4 (исключая)
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.005
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
больше 6 лет назад
LimeSurvey before v3.17.14 allows reflected XSS for escalating privile ...
EPSS
Процентиль: 65%
0.005
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79