PT-2022-12270 · Unknown · Limesurvey

Published

2022-02-22

·

Updated

2026-01-28

·

CVE-2021-44967

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LimeSurvey version 5.2.4
Description A Remote Code Execution (RCE) issue exists via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.
Recommendations For LimeSurvey version 5.2.4, consider disabling the upload and install plugins function until a patch is available to prevent exploitation. Restrict access to the plugin installation feature to minimize the risk of uploading malicious PHP code files.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BIT-LIMESURVEY-2021-44967
CVE-2021-44967

Affected Products

Limesurvey