vendor:
                    LimeSurvey Community Edition
                by:
                    Subhankar Singh
                8.1
                        CVSS
                    CRITICAL
                    Stored Cross-Site Scripting (XSS)
                    79
                        CWE
                    Product Name: LimeSurvey Community Edition
                    Affected Version From:  5.3.32+220817
                    Affected Version To:  5.3.32+220817
                    Patch Exists: NO
                    Related CWE: CVE-2024-24506
                    CPE:  a:limesurvey:limesurvey:5.3.32+220817
                    Platforms Tested:  Windows
                    2024
                    Stored Cross-Site Scripting (XSS) in LimeSurvey Community Edition Version 5.3.32+220817
A critical security vulnerability in LimeSurvey Community Edition Version 5.3.32+220817 allows attackers to compromise the super-admin account through the 'Administrator email address:' field in 'General Setting.' This could result in theft of cookies and session tokens.
Mitigation:
					To mitigate this vulnerability, it is recommended to sanitize user input by implementing proper input validation and output encoding. Additionally, restricting special characters in input fields can help prevent XSS attacks.