PT-2014-6248 · Limesurvey · Limesurvey
Publicado
2014-07-21
·
Atualizado
2014-07-22
·
CVE-2014-5016
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LimeSurvey versions 2.05 and later
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved through the
pid attribute to the getAttribute json function in application/controllers/admin/participantsaction.php in CPDB, the sa parameter to application/views/admin/globalSettings view.php, or a crafted CSV file to the "Import CSV" functionality.Recommendations
For LimeSurvey version 2.05 and later, consider disabling the
getAttribute json function and restricting access to the "Import CSV" functionality until a patch is available. Avoid using the sa parameter in the affected view until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Limesurvey