vendor:
LimeSurvey Community Edition
by:
Subhankar Singh
8.1
CVSS
CRITICAL
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: LimeSurvey Community Edition
Affected Version From: 5.3.32+220817
Affected Version To: 5.3.32+220817
Patch Exists: NO
Related CWE: CVE-2024-24506
CPE: a:limesurvey:limesurvey:5.3.32+220817
Platforms Tested: Windows
2024
Stored Cross-Site Scripting (XSS) in LimeSurvey Community Edition Version 5.3.32+220817
A critical security vulnerability in LimeSurvey Community Edition Version 5.3.32+220817 allows attackers to compromise the super-admin account through the 'Administrator email address:' field in 'General Setting.' This could result in theft of cookies and session tokens.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input by implementing proper input validation and output encoding. Additionally, restricting special characters in input fields can help prevent XSS attacks.