PT-2014-6248 · Limesurvey · Limesurvey
Published
2014-07-21
·
Updated
2014-07-22
·
CVE-2014-5016
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LimeSurvey versions 2.05 and later
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved through the
pid attribute to the getAttribute json function in application/controllers/admin/participantsaction.php in CPDB, the sa parameter to application/views/admin/globalSettings view.php, or a crafted CSV file to the "Import CSV" functionality.Recommendations
For LimeSurvey version 2.05 and later, consider disabling the
getAttribute json function and restricting access to the "Import CSV" functionality until a patch is available. Avoid using the sa parameter in the affected view until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Limesurvey