Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lacrioque

#21941of 53,638
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-16217
5.4
2020-12-31
Limesurvey · Limesurvey · CVE-2020-25797
**Name of the Vulnerable Software and Affected Versions** LimeSurvey version 3.21.1 **Description** The issue concerns cross-site scripting (XSS) in the Add Participants Function, specifically affecting the `First and last name` parameters. When a survey participant is being edited, for instance by an administrative user, the JavaScript code will be executed in the browser. **Recommendations** For LimeSurvey version 3.21.1, as a temporary workaround, consider restricting access to the Add Participants Function to minimize the risk of exploitation. Avoid using the `First and last name` parameters in this function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-16219
5.4
2020-12-31
Limesurvey · Limesurvey · CVE-2020-25799
**Name of the Vulnerable Software and Affected Versions** LimeSurvey version 3.21.1 **Description** The issue affects the Quota component of the Survey page, where cross-site scripting (XSS) can occur. When an administrative user views the survey quota, JavaScript code will be executed in the browser. **Recommendations** For LimeSurvey version 3.21.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.