Описание
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
Ссылки
- PatchRelease NotesThird Party Advisory
- Release NotesVendor Advisory
- PatchRelease NotesThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.17.14 (исключая)
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01128
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 8.8
debian
больше 6 лет назад
An XML injection vulnerability was found in Limesurvey before 3.17.14 ...
CVSS3: 8.8
github
больше 3 лет назад
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
EPSS
Процентиль: 78%
0.01128
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-611