vendor:
LimeSurvey
by:
@q3rv0
9.8
CVSS
CRITICAL
Serialization Attack
CWE
Product Name: LimeSurvey
Affected Version From: LimeSurvey < 3.16
Affected Version To: LimeSurvey 3.15
Patch Exists: YES
Related CWE: CVE-2018-17057
CPE: a:limesurvey:limesurvey:3.15
Platforms Tested:
2019
Remote Code Execution in LimeSurvey < 3.16 via Serialization Attack in TCPDF
LimeSurvey < 3.16 uses an old version of the 'TCPDF' library, which is vulnerable to a Serialization Attack via the 'phar://' wrapper.
Mitigation:
Upgrade to LimeSurvey version 3.16 or newer. Remove the vulnerable 'TCPDF' library.