PT-2014-6248 · Limesurvey · Limesurvey

Published

2014-07-21

·

Updated

2014-07-22

·

CVE-2014-5016

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LimeSurvey versions 2.05 and later
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved through the pid attribute to the getAttribute json function in application/controllers/admin/participantsaction.php in CPDB, the sa parameter to application/views/admin/globalSettings view.php, or a crafted CSV file to the "Import CSV" functionality.
Recommendations For LimeSurvey version 2.05 and later, consider disabling the getAttribute json function and restricting access to the "Import CSV" functionality until a patch is available. Avoid using the sa parameter in the affected view until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5016

Affected Products

Limesurvey