vendor:
LimeSurvey
by:
Matthew Aberegg
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: LimeSurvey
Affected Version From: LimeSurvey 4.3.10+200812
Affected Version To: LimeSurvey 4.3.10+200812
Patch Exists: Yes
Related CWE: N/A
CPE: a:limesurvey:limesurvey
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04.4
2020
LimeSurvey 4.3.10 – ‘Survey Menu’ Persistent Cross-Site Scripting
A stored cross-site scripting vulnerability exists within the 'Survey Menu' functionality of the LimeSurvey administration panel. Vulnerable Parameters: Surveymenu[parent_id].
Mitigation:
The vendor has released a patch to address this vulnerability. The patch can be found at the following link: https://github.com/LimeSurvey/LimeSurvey/commit/3712854a8fd8d875c67640969a1d54c4d93d3676