PT-2014-6248 · Limesurvey · Limesurvey

Publicado

2014-07-21

·

Atualizado

2014-07-22

·

CVE-2014-5016

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LimeSurvey versions 2.05 and later
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved through the pid attribute to the getAttribute json function in application/controllers/admin/participantsaction.php in CPDB, the sa parameter to application/views/admin/globalSettings view.php, or a crafted CSV file to the "Import CSV" functionality.
Recommendations For LimeSurvey version 2.05 and later, consider disabling the getAttribute json function and restricting access to the "Import CSV" functionality until a patch is available. Avoid using the sa parameter in the affected view until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5016

Produtos afetados

Limesurvey