vendor:
LimeSurvey
by:
Matthew Aberegg, Michael Burkey
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: LimeSurvey
Affected Version From: LimeSurvey 4.1.11+200316
Affected Version To: LimeSurvey 4.1.11+200316
Patch Exists: YES
Related CWE: CVE-2020-11456
CPE: a:limesurvey:limesurvey:4.1.11+200316
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04.4
2020
LimeSurvey 4.1.11 – ‘Survey Groups’ Persistent Cross-Site Scripting
A stored cross-site scripting vulnerability exists within the 'Survey Groups' functionality of the LimeSurvey administration panel. The vulnerable parameter is 'title'.
Mitigation:
Ensure that user input is properly sanitized and validated before being stored and displayed.