vendor:
LimeSurvey
by:
Andreas Kolbeck, David Haintz, SEC Consult Vulnerability Lab
5.4
CVSS
MEDIUM
Stored and reflected XSS vulnerabilities
79,352,285
CWE
Product Name: LimeSurvey
Affected Version From: <= 3.17.13
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2019-16172, CVE-2019-16173
CPE: a:limesurvey:limesurvey
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Stored and reflected XSS vulnerabilities
LimeSurvey suffered from a vulnerability due to improper input and output validation. By exploiting this vulnerability an attacker could attack other users of the web application with JavaScript code, browser exploits or Trojan horses, or perform unauthorized actions in the name of another logged-in user.
Mitigation:
The vendor provides a patch which should be installed immediately. Furthermore, a thorough security analysis is highly recommended as only a short spot check has been performed and additional issues are to be expected.