Описание
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
Ссылки
- PatchRelease NotesThird Party Advisory
- Release NotesVendor Advisory
- PatchRelease NotesThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.17.14 (исключая)
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00577
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236
Связанные уязвимости
CVSS3: 9.8
debian
больше 6 лет назад
A CSV injection vulnerability was found in Limesurvey before 3.17.14 t ...
CVSS3: 9.8
github
больше 3 лет назад
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
EPSS
Процентиль: 68%
0.00577
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236