Логотип exploitDog
bind:CVE-2020-25798
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-25798

Количество 3

Количество 3

nvd логотип

CVE-2020-25798

около 5 лет назад

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2020-25798

около 5 лет назад

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-95p7-w2p2-hhg2

больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-25798

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

CVSS3: 5.4
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25798

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before ...

CVSS3: 5.4
0%
Низкий
около 5 лет назад
github логотип
GHSA-95p7-w2p2-hhg2

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу