PT-2024-30196 · Unknown · Limesurvey

Published

2024-09-03

·

Updated

2025-07-04

·

CVE-2024-42902

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LimeSurvey versions 6.6.2 and earlier
Description An issue in the js localize.php function allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter. This enables potential remote code execution.
Recommendations For LimeSurvey versions 6.6.2 and earlier, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the js localize.php function to minimize the risk of exploitation. Avoid using the lng parameter in the affected function until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BIT-LIMESURVEY-2024-42902
CVE-2024-42902

Affected Products

Limesurvey